CVE-2017-7413
Last modified
CVE-2017-7413 is a vulnerability of currently unknown severity. In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address.. EPSS estimates a 40.45% chance of exploitation in the next 30 days.
Description
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Horde | Groupware | <= 5.2.17 |
References
- https://lists.horde.org/archives/horde/Week-of-Mon-20170403/056767.htmlMailing List, Vendor Advisory
- https://lists.horde.org/archives/horde/Week-of-Mon-20170403/056767.htmlMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7413?
How severe is CVE-2017-7413?
How do I fix CVE-2017-7413?
Are you affected by CVE-2017-7413?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
