Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-40614


EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.


Published

2024-07-07T15:15:09.923

Last Modified

2024-11-21T17:15:14.190

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application egroupware egroupware < 23.1.20240624 Yes

References