Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-30349 PoC — IMP 安全漏洞

Source
Associated Vulnerability
Title:IMP 安全漏洞 (CVE-2025-30349)
Description:IMP是Horde开源的一个基于 web 的网络邮件系统。 IMP 6.2.27及之前版本存在安全漏洞,该漏洞源于通过特制的HTML电子邮件可能导致账户接管。
Description
Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload
Readme
# Horde IMP vulnerability – obfuscation via HTML encoding – XSS payload

Horde 5.2.23; IMP 6.2.27

The details of the vulnerability are explained in Details.md file.

The PoC creates and send an email with payload exploiting the vulnerability to the recipient. This kind of email has to be viewed in a Horde Web Client, not any client (like desktop client).
File Snapshot

[4.0K] /data/pocs/f21d152acffd6289daddb3c07d6e45d169dd8bbd ├── [2.2K] Details.md ├── [1.4K] PoC.py └── [ 362] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.