CVE-2011-4951

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/08/2012
Last modified:
11/04/2025

Description

Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:egroupware:egroupware:*:-:community:*:*:*:*:* 1.8.001.20110421 (including)
cpe:2.3:a:egroupware:egroupware_enterprise_line:*:*:*:*:*:*:*:* 11.1.20110711-1 (including)