Vulnerability record · CVE-2015-7984 · published 19 November 2015
CVE-2015-7984: Horde groupware cross-site request forgery vulnerability
Horde · Groupware
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to admin/cmdshell.php, (2) SQL queries via the sql parameter to admin/sqlshell.php, or (3) PHP code via the php parameter to admin/phpshell.php.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to admin/cmdshell.php, (2) SQL queries via the sql parameter to admin/sqlshell.php, or (3) PHP code via the php parameter to admin/phpshell.php.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://lists.horde.org/archives/announce/2015/001124.html | Vendor Advisory |
| http://lists.horde.org/archives/announce/2015/001137.html | Vendor Advisory |
| http://lists.horde.org/archives/announce/2015/001138.html | Vendor Advisory |
| http://www.debian.org/security/2015/dsa-3391 | Third Party Advisory |
| https://www.exploit-db.com/exploits/38765/ | Third Party AdvisoryVDB Entry |
| https://www.htbridge.com/advisory/HTB23272 | Exploit |
| http://lists.horde.org/archives/announce/2015/001124.html | Vendor Advisory |
| http://lists.horde.org/archives/announce/2015/001137.html | Vendor Advisory |
| http://lists.horde.org/archives/announce/2015/001138.html | Vendor Advisory |
| http://www.debian.org/security/2015/dsa-3391 | Third Party Advisory |
| https://www.exploit-db.com/exploits/38765/ | Third Party AdvisoryVDB Entry |
| https://www.htbridge.com/advisory/HTB23272 | Exploit |
Track CVE-2015-7984 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7984), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.