CVE-2015-7984 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities affecting Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11. These flaws allow remote attackers to hijack authenticated administrator sessions. The vulnerabilities enable the execution of arbitrary commands, SQL queries, or PHP code through specific administrative interfaces. With a CVSS score of 6.8 (Medium), the attack vector is network-based, requires medium attack complexity, and does not require authentication. Successful exploitation could lead to partial compromise of confidentiality, integrity, and availability. The EPSS score is low, suggesting a low probability of exploitation in the wild. While there is no evidence of active exploitation or Metasploit modules, an ExploitDB entry (EDB-38765) exists for Horde Groupware 5.2.10. There is minimal community discussion or media coverage surrounding this CVE, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.2.11CPE matchmatch criteria | cpe:2.3:a:horde:groupware:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.2.11CPE matchmatch criteria | cpe:2.3:a:horde:groupware:*:*:*:*:webmail:*:*:* | ||
>= 5.0.0, < 5.2.8CPE matchmatch criteria | cpe:2.3:a:horde:horde_application_framework:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.