CVE-2014-1691 | Horde Groupware up to 5.1.0 Util Library variables.php _formvars code injection (EDB-32439 / Nessus ID 72353)
A vulnerability was found in Horde Groupware up to 5.1.0. It has been rated as critical. This impacts an unknown function in the library framework/util/lib/horde/variables.php of the component Util Library. The manipulation of the argument _formvars leads to code injection.
This vulnerability is documented as CVE-2014-1691. The attack can be initiated remotely. Additionally, an exploit exists.
Upgrading the affected component is advised.