vendor:
eGroupWare
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting, HTML Injection
79
CWE
Product Name: eGroupWare
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:egroupware:egroupware
Platforms Tested:
Unknown
eGroupWare Multiple Cross-Site Scripting and HTML Injection Vulnerabilities
eGroupWare is susceptible to multiple cross-site scripting and HTML injection vulnerabilities. The cross-site scripting issues exist in the 'addressbook' and 'calendar' modules, as well as in the 'Search' functionality of the 'addressbook', 'calendar', and 'search between projects' modules. The HTML injection vulnerabilities are present in the 'Messenger' and 'Ticket' modules. These vulnerabilities can be exploited by attackers to steal cookie-based authentication credentials and manipulate web content.
Mitigation:
It is recommended to sanitize user input and implement proper input validation to prevent cross-site scripting and HTML injection attacks. Regular security updates and patches should be applied to address these vulnerabilities.