GHSA-qfg7-wc25-r3j2
Dashboard / Vulnerabilities / GHSA-qfg7-wc25-r3j2
Summary: eGroupware Community Edition Stored XSS vulnerability
Details: Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-14920, https://github.com/EGroupware/egroupware/commit/0ececf8c78f1c3f9ba15465f53a682dd7d89529f, https://github.com/EGroupware/egroupware, http://openwall.com/lists/oss-security/2017/09/28/12
Affected packages
Package
Name: egroupware/egroupware
Purl: pkg:composer/egroupware/egroupware
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -16.1.20170922
Affected versions
14.2.20150121
14.2.20150206
14.2.20150210
14.2.20150212
14.2.20150218
14.2.20150310
14.2.20150402
14.2.20150421
14.2.20150428
14.2.20150429
14.2.20150501
14.2.20150603
14.2.20150707
14.2.20150717
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
