CVE-2022-30287 Information

Description

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

Reference

https://blog.sonarsource.com/horde-webmail-rce-via-email/ https://www.horde.org/apps/webmail

Share on: