CVE-2022-30287
high · 8Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
8
CVSS
70.7%
EPSS (exploit prob.)
99th
EPSS percentile
2022-07-28
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-470CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| horde | groupware | <= 5.2.22 |
| debian | debian_linux | 10.0 |
Check a specific version with /api/v1/cve/match.
References
- https://blog.sonarsource.com/horde-webmail-rce-via-email/
- https://lists.debian.org/debian-lts-announce/2022/08/msg00022.html
- https://www.horde.org/apps/webmail
- https://blog.sonarsource.com/horde-webmail-rce-via-email/
- https://lists.debian.org/debian-lts-announce/2022/08/msg00022.html
- https://lists.debian.org/debian-lts-announce/2024/10/msg00014.html
- https://www.horde.org/apps/webmail
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-30287