4.3
CVSSv2

CVE-2013-6275

Published: 05/11/2019 Updated: 18/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and previous versions in basic.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

horde groupware

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #727669 Protect against CSRF attacks by using tokens on destructive actions (CVE-2013-6275) Package: php-horde-ingo; Maintainer for php-horde-ingo is Horde Maintainers <team+debian-horde-team@trackerdebianorg>; Source for php-horde-ingo is src:php-horde-ingo (PTS, buildd, popcon) Reported by: Mike ...

Exploits

############################# Exploit Title : Multiple CSRF Horde Groupware Web mail Edition Author:Marcela Benetrix Date: 10/25/13 version: 512 software link:wwwhordeorg/apps/webmail ############################# GroupWare Web mail Edition Horde Groupware Webmail Edition is a free, enterprise ready, browser based communication suite ...
Horde Groupware Web Mail Edition version 512 suffers from multiple cross site request forgery vulnerabilities ...