Description
The IMP is a web-based mail client for IMAP and POP3 accounts. It is built atop the Horde Application Framework, which is a general-purpose web application library written in PHP.
A vulnerability in Horde IMP could allow unauthenticated command execution via imap_open in an exposed debug page.
Remediation
The IMP debug page (accessible at http://example.com/horde/imp/test.php) should be deleted after installation.
References
Related Vulnerabilities
WordPress Plugin Ad Inserter-Ad Manager & AdSense Ads Remote Code Execution (2.4.21)
WordPress Plugin eShop Code Injection (6.3.11)
WordPress Plugin WooCommerce Remote Code Execution (4.0.1)
Tiki Wiki CMS: Remote Code Execution via Calendar Module
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-21650)