CRITICAL
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution
Published Feb 17, 2020
9.8
CRITICALCVSS 3.1
EPSS 71.73%
Description
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Affected products
No data.
Configuration 2
OR
- 30
- 31
Configuration 3
- 8.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://packetstormsecurity.com/files/156872/Horde-5.2.22-CSV-Import-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2020/04/msg00008.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PRPIFQDGYPQ3F2TF2ETPIL7IYNSVVZQ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKTNYDBDVJNMVC7QPXQI7CMPLX3USZ2T/ vendor-advisoryx_refsource_FEDORA
- https://lists.horde.org/archives/announce/2020/001285.html x_refsource_CONFIRMMailing ListVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/156872/Horde-5.2.22-CSV-Import-Code-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://lists.debian.org/debian-lts-announce/2020/04/msg00008.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PRPIFQDGYPQ3F2TF2ETPIL7IYNSVVZQ/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKTNYDBDVJNMVC7QPXQI7CMPLX3USZ2T/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.horde.org/archives/announce/2020/001285.html | x_refsource_CONFIRMMailing ListVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 17, 2020
Updated Aug 4, 2024
Reserved Feb 3, 2020
Link CVE-2020-8518
CISA Vulnrichment
Updated n/a