CVE ID | CVE-2020-8866 |
CVSS SCORE | 4.3, AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
AFFECTED VENDORS |
Horde |
AFFECTED PRODUCTS |
Groupware Webmail Edition |
VULNERABILITY DETAILS |
The specific flaw exists within add.php. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. |
ADDITIONAL DETAILS |
Horde has issued an update to correct this vulnerability. More details can be found at:
https://lists.horde.org/archives/announce/2020/001288.html |
DISCLOSURE TIMELINE |
|
CREDIT | Andrea Cardaci |