Vulnerability record · CVE-2022-30287 · published 28 July 2022
CVE-2022-30287: Horde Groupware Webmail reflection injection leads to PHP object deserialization
Horde · Groupware
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack in which an attacker can instantiate a driver class, leading to arbitrary deserialization of PHP objects. Because deserialization of attacker-controlled data can reach dangerous magic methods, this can escalate to remote code execution on the mail server. The flaw matters because webmail is internet-facing and the referenced exploit write-up describes RCE via email.
Description
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable deserialization with a public exploit write-up and very high EPSS, though it requires authentication and user interaction and is not in KEV.
What it is
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack in which an attacker can instantiate a driver class, leading to arbitrary deserialization of PHP objects. Because deserialization of attacker-controlled data can reach dangerous magic methods, this can escalate to remote code execution on the mail server. The flaw matters because webmail is internet-facing and the referenced exploit write-up describes RCE via email.
Impact
An attacker who can trigger the vulnerable path can deserialize arbitrary PHP objects, which can lead to remote code execution and full compromise of the webmail host and its stored mail.
Attack surface
Reached over the network through the webmail application; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so an authenticated user must be induced to interact with crafted content.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.70651, 99.36th percentile) and a public third-party exploit write-up is referenced, indicating mature public exploitation knowledge.
What to do
- Upgrade Horde Groupware Webmail Edition past 5.2.22 to a fixed release, or apply the Debian LTS security update for the packaged version.
- If immediate patching is not possible, restrict or disable the affected webmail functionality and limit access to trusted networks.
- Enforce least privilege on the webmail service account and isolate the webmail host from other internal systems.
- Monitor vendor and Debian security advisories for follow-up fixes and re-check exposure after each update.
Detection
- Review webmail and PHP logs for unexpected class instantiation or deserialization errors tied to user-supplied input.
- Hunt for suspicious outbound connections or process execution originating from the webmail server.
- Alert on anomalous file writes or new files in webmail application directories.
- Correlate webmail access logs with POST requests containing serialized object patterns or unusual driver-class parameters.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.sonarsource.com/horde-webmail-rce-via-email/ | ExploitThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/08/msg00022.html | Mailing ListThird Party Advisory |
| https://www.horde.org/apps/webmail | Release NotesVendor Advisory |
| https://blog.sonarsource.com/horde-webmail-rce-via-email/ | ExploitThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/08/msg00022.html | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2024/10/msg00014.html | |
| https://www.horde.org/apps/webmail | Release NotesVendor Advisory |
Track CVE-2022-30287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-30287), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.