PT-2015-7692 · Horde · Horde Groupware Webmail Edition+2

Published

2015-11-03

·

Updated

2021-05-19

·

CVE-2015-7984

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Horde versions prior to 5.2.8 Horde Groupware versions prior to 5.2.11 Horde Groupware Webmail Edition versions prior to 5.2.11
Description Multiple cross-site request forgery (CSRF) issues allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands, SQL queries, or PHP code. This is achieved via the cmd parameter to "admin/cmdshell.php", the sql parameter to "admin/sqlshell.php", or the php parameter to "admin/phpshell.php".
Recommendations For Horde versions prior to 5.2.8, update to version 5.2.8 or later. For Horde Groupware versions prior to 5.2.11, update to version 5.2.11 or later. For Horde Groupware Webmail Edition versions prior to 5.2.11, update to version 5.2.11 or later. As a temporary workaround, consider restricting access to the "admin/cmdshell.php", "admin/sqlshell.php", and "admin/phpshell.php" endpoints until a patch is applied.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7984
DLA-2350-1
DSA-3391-1

Affected Products

Horde
Horde Groupware
Horde Groupware Webmail Edition