CVE-2020-8865

Source
https://cve.org/CVERecord?id=CVE-2020-8865
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8865.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-8865
Downstream
Published
2020-03-23T21:15:12.567Z
Modified
2026-07-08T05:56:48.952388096Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template] parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. Was ZDI-CAN-10469.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.0"
                },
                {
                    "last_affected": "8.0"
                }
            ],
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "debian:debian_linux",
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/horde/groupware

Affected ranges

Type
GIT
Repo
https://github.com/horde/groupware
Events
Database specific
{
    "cpe": "cpe:2.3:a:horde:groupware:5.2.22:*:*:*:webmail:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "5.2.22"
        },
        {
            "last_affected": "5.2.22"
        }
    ]
}

Affected versions

5.*
5.2.22
v5.*
v5.2.22

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8865.json"

Git / github.com/horde/horde

Affected ranges

Type
GIT
Repo
https://github.com/horde/horde
Events
Database specific
{
    "cpe": "cpe:2.3:a:horde:groupware:5.2.22:*:*:*:webmail:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.2.22"
        },
        {
            "last_affected": "5.2.22"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

5.*
5.2.22
webmail-5.*
webmail-5.2.22

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8865.json"