← Back to CVE List

CVE-2017-7413

Published: 2017-04-04T14:59Z
Last Modified: 2024-11-21T03:31Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt