PT-2017-19178 · Horde · Horde Image

Fariskhi Vidyan

+1

·

Published

2017-06-21

·

Updated

2018-08-18

·

CVE-2017-9774

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Horde Image versions prior to 2.5.0
Description A Remote Code Execution issue was discovered, which can be exploited via a crafted GET request. This issue requires authentication to be exploited.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected module to minimize the risk of exploitation.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9774
DLA-1395-1
DSA-4276-1

Affected Products

Horde Image