GHSA-qfg7-wc25-r3j2

    Dashboard / Vulnerabilities / GHSA-qfg7-wc25-r3j2

    GHSA-qfg7-wc25-r3j2

    Published: 17 May 2022Last Modified: 25 Apr 2024

    Summary: eGroupware Community Edition Stored XSS vulnerability

    Details: Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.

    Affected packages

    Package

    Name: egroupware/egroupware

    Purl: pkg:composer/egroupware/egroupware

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -16.1.20170922

    Affected versions

    14.2.20150121
    14.2.20150206
    14.2.20150210
    14.2.20150212
    14.2.20150218
    14.2.20150310
    14.2.20150402
    14.2.20150421
    14.2.20150428
    14.2.20150429
    14.2.20150501
    14.2.20150603
    14.2.20150707
    14.2.20150717

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-qfg7-wc25-r3j2 | CVE-DB