CVE-2017-15235: Horde Groupware

High severity, CVSS 7.5. EPSS: 5.5% chance of exploitation in the next 30 days.

The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.

Affected products

  • Horde Groupware: version 5.2.21 only

Published 2017-10-11. Last modified 2026-06-17.