Vulnerabilities > CVE-2022-30287 - Unsafe Reflection vulnerability in multiple products

047910
CVSS 8.0 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
horde
debian
CWE-470

Summary

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

Vulnerable Configurations

Part Description Count
Application
Horde
89
OS
Debian
1