CVE-2020-8518: Code Injection
Published Feb 17, 2020
·Updated
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Affected Software
4 affected components
Horde Groupware=5.2.22
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Debian Debian Linux=8.0
Event History
Feb 17, 2020
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-8518?
CVE-2020-8518 is a vulnerability in Horde Groupware Webmail Edition 5.2.22 that allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
2
How severe is CVE-2020-8518?
CVE-2020-8518 has a severity rating of critical (9.8).
3
What software is affected by CVE-2020-8518?
Horde Groupware Webmail Edition 5.2.22, Fedoraproject Fedora 30 and 31, and Debian Debian Linux 8.0 are affected by CVE-2020-8518.
4
How can an attacker exploit CVE-2020-8518?
An attacker can exploit CVE-2020-8518 by injecting arbitrary PHP code via CSV data, which can lead to remote code execution.
5
How can I fix CVE-2020-8518?
To fix CVE-2020-8518, it is recommended to update Horde Groupware Webmail Edition to a secure version and apply any patches provided by the vendor.