This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22
Published Mar 23, 2020
6.3
MEDIUMCVSS 3.1
EPSS 6.81%
Description
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template] parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. Was ZDI-CAN-10469.
Affected products
-
Affected
- 5.2.22
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Horde | Groupware Webmail Edition | unknown | Affected
|
Configuration 2
- 8.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29707 Advisory
- https://lists.debian.org/debian-lts-announce/2020/04/msg00009.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-276/ x_refsource_MISCThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29707 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/04/msg00009.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://www.zerodayinitiative.com/advisories/ZDI-20-276/ | x_refsource_MISCThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data