SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-0807

lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights,…

MEDIUM 4.9EPSS 1.38%

Does this matter?

Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.

Description

lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.

CVSS 2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
EPSS
1.38% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
horde/groupware · horde/groupware webmail edition · horde/turba contact manager
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.