Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-15235. PoCs published by SecuriTeam.
AI-analyzed exploit summary The vulnerability in Horde Groupware version 5.2.21 allows unauthorized file downloads via the Gollem module due to insufficient sanitization of the 'fn' parameter. An attacker can download files by knowing the username and file path.
Description
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.
Exploits (1)
The vulnerability in Horde Groupware version 5.2.21 allows unauthorized file downloads via the Gollem module due to insufficient sanitization of the 'fn' parameter. An attacker can download files by knowing the username and file path.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N