Debian Php-Horde-Gollem vulnerabilities
2 known vulnerabilities affecting debian/php-horde-gollem.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-8034MEDIUMCVSS 6.1fixed in php-horde-gollem 3.0.12-6 (bookworm)2020
CVE-2020-8034 [MEDIUM] CVE-2020-8034: php-horde-gollem - Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and othe...
Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
Scope: loca
debian
CVE-2017-15235HIGHCVSS 7.5PoCfixed in php-horde-gollem 3.0.12-1 (bookworm)2017
CVE-2017-15235 [HIGH] CVE-2017-15235: php-horde-gollem - The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote ...
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.
Scope: local
bookworm: resolved (fixed in 3.0.12-1)
bullseye: resolved (fixed in 3.0.12-1)
sid: resolved (fixed in 3.0.12-1)
debian