Описание
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
Ссылки
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
EPSS
8 High
CVSS3
Дефекты
Связанные уязвимости
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
Horde Groupware Webmail Edition through 5.2.22 allows a reflection inj ...
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
Уязвимость функции create программного средства Horde Webmail, позволяющая нарушителю выполнить произвольный код
EPSS
8 High
CVSS3