Added |
CPE Configuration |
|
OR
*cpe:2.3:a:horde:groupware:*:*:*:*:webmail:*:*:* versions up to (including) 5.2.22 |
Added |
CVSS V2 |
|
NIST (AV:N/AC:M/Au:N/C:P/I:P/A:P) |
Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism |
Added |
CVSS V3.1 |
|
NIST AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Added |
CWE |
|
NIST CWE-352 |
Changed |
Reference Type |
https://bugs.horde.org/ticket/14926 No Types Assigned |
https://bugs.horde.org/ticket/14926 Exploit, Issue Tracking, Vendor Advisory |
Changed |
Reference Type |
https://cxsecurity.com/issue/WLB-2019050199 No Types Assigned |
https://cxsecurity.com/issue/WLB-2019050199 Exploit, Third Party Advisory |
Changed |
Reference Type |
https://exchange.xforce.ibmcloud.com/vulnerabilities/161333 No Types Assigned |
https://exchange.xforce.ibmcloud.com/vulnerabilities/161333 Third Party Advisory, VDB Entry |
Changed |
Reference Type |
https://numanozdemir.com/respdisc/horde/horde.mp4 No Types Assigned |
https://numanozdemir.com/respdisc/horde/horde.mp4 Exploit, Third Party Advisory |
Changed |
Reference Type |
https://numanozdemir.com/respdisc/horde/horde.txt No Types Assigned |
https://numanozdemir.com/respdisc/horde/horde.txt Exploit, Third Party Advisory |
Changed |
Reference Type |
https://packetstormsecurity.com/files/152975/Horde-Webmail-5.2.22-XSS-CSRF-SQL-Injection-Code-Execution.html No Types Assigned |
https://packetstormsecurity.com/files/152975/Horde-Webmail-5.2.22-XSS-CSRF-SQL-Injection-Code-Execution.html Exploit, Third Party Advisory, VDB Entry |
Changed |
Reference Type |
https://www.exploit-db.com/exploits/46903 No Types Assigned |
https://www.exploit-db.com/exploits/46903 Exploit, Third Party Advisory, VDB Entry |