CVE-2017-15235

HIGH

Horde Groupware <5.2.21 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-15235. PoCs published by SecuriTeam.

AI-analyzed exploit summary The vulnerability in Horde Groupware version 5.2.21 allows unauthorized file downloads via the Gollem module due to insufficient sanitization of the 'fn' parameter. An attacker can download files by knowing the username and file path.

Description

The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.

Exploits (1)

exploitdb WRITEUP
by SecuriTeam · webappsphp
https://www.exploit-db.com/exploits/44059

The vulnerability in Horde Groupware version 5.2.21 allows unauthorized file downloads via the Gollem module due to insufficient sanitization of the 'fn' parameter. An attacker can download files by knowing the username and file path.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Horde Groupware 5.2.21
No auth needed
Prerequisites: knowledge of the target username · knowledge of the target file path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/3454
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/08/msg00050.html

Scores

CVSS v3 7.5
EPSS 0.0553
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-425
Status published
Products (1)
horde/groupware 5.2.21
Published Oct 11, 2017
Tracked Since Feb 18, 2026