CVE-2017-15235: Horde Groupware
High severity, CVSS 7.5. EPSS: 5.5% chance of exploitation in the next 30 days.
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.
Affected products
- Horde Groupware: version 5.2.21 only
Published 2017-10-11. Last modified 2026-06-17.