Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
2022-07-28T22:15:08.373
2024-11-21T07:02:30.240
Modified
CVSSv3.1: 8.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | horde | groupware | ≤ 5.2.22 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |