Vulnerability record · CVE-2020-8518 · published 17 February 2020
CVE-2020-8518: Horde Groupware Webmail CSV import PHP code injection
Horde · Groupware
Horde Groupware Webmail Edition 5.2.22 permits injection of arbitrary PHP code through CSV data, resulting in remote code execution. The flaw is a code injection (CWE-94) reachable over the network with no privileges or user interaction required, so any exposed instance is a high-value target.
Description
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and public exploit code makes this a critical remote code execution risk.
What it is
Horde Groupware Webmail Edition 5.2.22 permits injection of arbitrary PHP code through CSV data, resulting in remote code execution. The flaw is a code injection (CWE-94) reachable over the network with no privileges or user interaction required, so any exposed instance is a high-value target.
Impact
An attacker can execute arbitrary PHP code on the server, gaining full control of the webmail host and any data or credentials it processes.
Attack surface
Reached over the network via the CSV import functionality; the CVSS vector indicates no authentication (PR:N) and no user interaction (UI:N) are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.717 probability, 99.4th percentile) and public exploit code is referenced on Packet Storm, indicating active interest and likely weaponization.
What to do
- Upgrade Horde Groupware Webmail Edition to a fixed release per the vendor advisory (lists.horde.org/archives/announce/2020/001285.html).
- Apply the Debian LTS and Fedora package updates for affected distributions.
- Restrict or disable CSV import functionality until patched.
- Limit network exposure of the webmail interface to trusted users or networks.
- Monitor and review web server logs for suspicious CSV upload activity.
Detection
- Inspect web server and application logs for CSV import requests containing PHP code or unusual serialized payloads.
- Monitor for unexpected PHP file creation or modification in web-accessible directories.
- Alert on outbound connections or process spawning from the webmail server process.
- Use file integrity monitoring on Horde installation directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-8518 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8518), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.