CVE-2017-14920

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
30/09/2017
Last modified:
20/04/2025

Description

Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:egroupware:egroupware:*:*:*:*:community:*:*:* 16.1.20170703 (including)