SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-6018

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2)…

MEDIUM 5.8EPSS 1.77%

Does this matter?

Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.

Description

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.77% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
horde/framework · horde/groupware webmail edition · horde/horde · horde/imp
Source
PSIRT-CNA@flexerasoftware.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.