First published: Mon Feb 17 2020(Updated: )
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware | =5.2.22 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8518 is a vulnerability in Horde Groupware Webmail Edition 5.2.22 that allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
CVE-2020-8518 has a severity rating of critical (9.8).
Horde Groupware Webmail Edition 5.2.22, Fedoraproject Fedora 30 and 31, and Debian Debian Linux 8.0 are affected by CVE-2020-8518.
An attacker can exploit CVE-2020-8518 by injecting arbitrary PHP code via CSV data, which can lead to remote code execution.
To fix CVE-2020-8518, it is recommended to update Horde Groupware Webmail Edition to a secure version and apply any patches provided by the vendor.