[horde] [SECURITY] Horde Groupware 5.2.10 (final)

Michael J Rubinsky mrubinsk at horde.org
Thu Aug 6 02:06:10 UTC 2015


The Horde Team is pleased to announce the final release of the Horde Groupware
version 5.2.10.

Horde Groupware is a free, enterprise ready, browser based collaboration
suite. Users can manage and share calendars, contacts, tasks, notes,  
files, and
bookmarks with the standards compliant components from the Horde Project.

For upgrading instructions, please see
http://www.horde.org/apps/groupware/docs/UPGRADING

For detailed installation and configuration instructions, please see
http://www.horde.org/apps/groupware/docs/INSTALL

Thanks to an anonymous researcher working with Beyond Security's SecuriTeam
Secure Disclosure program <http://www.beyondsecurity.com/ssd.html> for
discovering the vulnerability.

The major changes compared to the Horde Groupware version 5.2.9 are:
     * SECURITY: Fix XSS vulnerability in Files application when viewing
       directory contents.

The full list of changes can be viewed here:

https://github.com/horde/horde/blob/3ec88b3832ceb6d9fdc9ffb96b3d4179e5c4aedc/bundles/groupware/docs/CHANGES

Have fun!

The Horde Team.


More information about the horde mailing list