CVE-2022-30287: High severity horde groupware webmail edition vulnerability
Published Jul 28, 2022
·Updated
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
Affected Software
2 affected components
Horde Groupware<=5.2.22
Debian Debian Linux=10.0
Event History
Jul 28, 2022
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-30287.
2
What is the title of this vulnerability?
The title of this vulnerability is Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack.
3
What is the severity level of CVE-2022-30287?
The severity level of CVE-2022-30287 is high.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by performing a reflection injection attack to instantiate a driver class, which leads to arbitrary deserialization of PHP objects.
5
How can I fix CVE-2022-30287?
To fix CVE-2022-30287, it is recommended to update Horde Groupware Webmail Edition to a version beyond 5.2.22.