Product:

Egroupware

(Egroupware)
Repositories https://github.com/EGroupware/egroupware
#Vulnerabilities 22
Date Id Summary Products Score Patch Annotated
2023-10-26 CVE-2023-38328 An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of under setup/manageheader.php, which allows authenticated remote attackers with administrator credentials to read a cleartext database password. Egroupware 4.9
2024-07-07 CVE-2024-40614 EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting. Egroupware 9.8