CVE-2020-8034Cross-site Scripting in Gollem

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 34.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 18
Latest updateMay 24

Description

Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDhorde/gollem< 3.0.13
debiandebian/php-horde-gollem< php-horde-gollem 3.0.12-6 (bookworm)
NVDhorde/groupware5.2.22

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4653-jj47-h6j5: Gollem before 32022-05-24
OSV
CVE-2020-8034: Gollem before 32020-05-18

📋Vendor Advisories

1
Debian
CVE-2020-8034: php-horde-gollem - Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and othe...2020