Filtered by vendor Egroupware Subscriptions
Filtered by product Egroupware Subscriptions
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-14920 1 Egroupware 1 Egroupware 2024-08-05 N/A
Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.
CVE-2024-40614 1 Egroupware 1 Egroupware 2024-08-02 9.8 Critical
EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.