Show filters
194 Total Results
Displaying 1-10 of 194
Sort by:
Attacker Value
Unknown

CVE-2024-40614

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.
Attacker Value
Unknown

CVE-2023-45800

Disclosure Date: December 13, 2023 (last updated December 16, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hanbiro Hanbiro groupware allows Information Elicitation.This issue affects Hanbiro groupware: from V3.8.79 before V3.8.81.1.
Attacker Value
Unknown

CVE-2023-38328

Disclosure Date: October 26, 2023 (last updated November 08, 2023)
An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of under setup/manageheader.php, which allows authenticated remote attackers with administrator credentials to read a cleartext database password.
Attacker Value
Unknown

CVE-2022-30287

Disclosure Date: July 28, 2022 (last updated November 29, 2024)
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
Attacker Value
Unknown

CVE-2021-26630

Disclosure Date: May 19, 2022 (last updated October 07, 2023)
Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.
Attacker Value
Unknown

CVE-2022-26562

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced between 6.30.0 RC1e and 6.30.8 final).
Attacker Value
Unknown

CVE-2021-36551

Disclosure Date: October 28, 2021 (last updated November 28, 2024)
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.
Attacker Value
Unknown

CVE-2021-36550

Disclosure Date: October 28, 2021 (last updated November 28, 2024)
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.
Attacker Value
Unknown

CVE-2021-28994

Disclosure Date: March 31, 2021 (last updated February 22, 2025)
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.
Attacker Value
Unknown

CVE-2021-26929

Disclosure Date: February 14, 2021 (last updated February 22, 2025)
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in Text2html.php, because bespoke use of \x00\x00\x00 and \x01\x01\x01 interferes with XSS defenses.