vendor:
Horde Groupware Webmail Edition
by:
Juan Pablo Lopez Yacubian
7,5
CVSS
HIGH
Unauthorized File Download
20
CWE
Product Name: Horde Groupware Webmail Edition
Affected Version From: Horde Groupware 5.2.21
Affected Version To: Horde Groupware 5.2.21
Patch Exists: YES
Related CWE: CVE-2017-15235
CPE: a:horde:horde_groupware_webmail_edition
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Unauthorized File Download Vulnerability in Horde Groupware
User controlled input is not sufficiently sanitized when passed to File Manager (gollem) module (version 3.0.11). The “fn” parameter does not validate certain met characters by causing the requested file or filesystem to be downloaded without credentials. It is only necessary to know the username and the file name.
Mitigation:
Horde Groupware has already released a patch to fix this vulnerability.