8
CVSSv3

CVE-2022-30287

Published: 28/07/2022 Updated: 08/08/2023
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 0

Vulnerability Summary

Horde Groupware Webmail Edition up to and including 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

horde groupware

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1012279 php-horde-turba: CVE-2022-30287 Package: src:php-horde-turba; Maintainer for src:php-horde-turba is Horde Maintainers <team+debian-horde-team@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 2 Jun 2022 20:33:02 UTC Severity: grave Tags: security, ...