CVE detail
CVE-2014-1691 — CVE-2014-1691
Published 2014-04-01 · Modified 2026-06-17 · Vendor horde · Product horde_application_framework · Source nvd
UNKNOWN
severity
CVSS-derived band
0.4289
EPSS probability
exploitation probability, 30d
99.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References