EGroupware 14.1.20141112 Community Edition

CPE Details

EGroupware 14.1.20141112 Community Edition
14.1.20141112
2020-06-01
15h33 +00:00
2020-06-01
15h33 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:egroupware:egroupware:14.1.20141112:*:*:*:community:*:*:*

Informations

Vendor

egroupware

Product

egroupware

Version

14.1.20141112

Software Edition

community

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-40614 2024-07-06 22h00 +00:00 EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.
9.8
Critique
CVE-2017-14920 2017-09-29 05h00 +00:00 Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.
6.1
Moyen