[horde] Question on: (0Day) Horde Groupware Webmail Edition Sort sortpref Deserialization of Untrusted Data Remote Code Execution Vulnerability
wahnes at uni-koeln.de
Wed Oct 12 13:02:02 UTC 2022
Frank Richter wrote:
> I stumbled over this:
> Ist this one fixed in the current versions?
The report mentions that the flaw is in "Sort.php". If that information
is correct, then the flaw still exists, because "Sort.php" has not been
updated since 2017 but the bug was reported to have existed in 2020.
See <https://github.com/horde/imp/commits/master/lib/Prefs/Sort.php> or
for a history of updates to "Sort.php".
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 5324 bytes
Desc: S/MIME Cryptographic Signature
More information about the horde