V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2020-8865
DEB
MediumConfirmedExploit available

This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. …

CVSS
6.3
Medium
EPSS
0.04
p88
Published
2020-01-01
Updated
2020-01-01
Description

This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template] parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. Was ZDI-CAN-10469.

Tags · CWE
CWE-23
CAPEC-76
CAPEC-139
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.039 · p88
Known exploited (KEV)
No
Known exploits — Сканер-ВС
48209
exploitdb · https://www.exploit-db.com/exploits/48209
Enterprise
48210
exploitdb · https://www.exploit-db.com/exploits/48210
Enterprise
Affected software
ProductVendorStatus
php-horde-treanTracked
php-horde-treanTracked
php-horde-treanTracked
php-horde-treanTracked
php-horde-treanTracked
php-horde-treanTracked
php-horde-treanTracked
debian_linux*Tracked
groupware*Tracked
Source databases
DEB
CVE
UBU