CVE-2020-8866: Horde Groupware Webmail Edition add Page Unrestricted File Upload Arbitrary File Creation Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within add.php. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. Was ZDI-CAN-10125.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8866?
CVE-2020-8866 is a vulnerability that allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22.
How severe is CVE-2020-8866?
CVE-2020-8866 has a severity rating of 6.5, which is considered medium.
What software is affected by CVE-2020-8866?
Horde Groupware Webmail Edition 5.2.22 and Horde Horde Form up to version 2.0.0 are affected.
How can this vulnerability be exploited?
This vulnerability can be exploited by authenticated remote attackers using the add.php page of Horde Groupware Webmail Edition.
Are there any references for CVE-2020-8866?
Yes, you can find more information about CVE-2020-8866 at the following references: [Reference 1](https://lists.debian.org/debian-lts-announce/2020/03/msg00036.html), [Reference 2](https://lists.horde.org/archives/announce/2020/001288.html), [Reference 3](https://www.zerodayinitiative.com/advisories/ZDI-20-275/).