vendor:
EGroupware
by:
High-Tech Bridge Security Research Lab
7.5
CVSS
HIGH
Cross-Site Request Forgery [CWE-352], Code Injection [CWE-94]
352, 94
CWE
Product Name: EGroupware
Affected Version From: 1.8.006 community edition and probably prior
Affected Version To: 1.8.006 community edition
Patch Exists: YES
Related CWE: CVE-2014-2987, CVE-2014-2988
CPE: EGroupware
Platforms Tested:
2014
Advisory ID: HTB23212
High-Tech Bridge Security Research Lab discovered CSRF and Remote Code Execution vulnerabilities in EGroupware, which can be exploited by remote attacker to gain full control over the application and compromise vulnerable system.
Mitigation:
Fixed by Vendor