CVE-2015-7984

EUVD-2015-7880
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to admin/cmdshell.php, (2) SQL queries via the sql parameter to admin/sqlshell.php, or (3) PHP code via the php parameter to admin/phpshell.php.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
hordegroupware
5.0.0 ≤
𝑥
< 5.2.11
hordegroupware
5.0.0 ≤
𝑥
< 5.2.11
hordehorde_application_framework
5.0.0 ≤
𝑥
< 5.2.8
debiandebian_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-horde
bookworm
5.2.23+debian0-6
fixed
bullseye
5.2.23+debian0-5
fixed
sid
5.2.23+debian0-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php-horde
artful
ignored
bionic
not-affected
cosmic
not-affected
disco
not-affected
precise
dne
trusty
dne
vivid
Fixed 5.2.1+debian0-2+deb8u2build0.15.04.1
released
wily
ignored
xenial
not-affected
yakkety
ignored
zesty
ignored