IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.
📦
imp
Vendor: horde
Actively Exploited
0
CISA KEV List
PoC / Exploits
4
Code Available
Total RCEs
0
Remote Access
Total CVEs
273
Total Indexed
Avg. EPSS
2.98%
Exploit Prob.
Security Vulnerability Index
Page 3 / 28
5.0
CVSS
Severity: MEDIUM
5.0
CVSS
IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.
Severity: MEDIUM
2.1
CVSS
The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.
Severity: LOW