PT-2014-9129 · Egroupware · Egroupware

Published

2014-05-17

·

Updated

2014-05-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions eGroupWare versions prior to 1.8.007
Description The issue allows logged-in users with administrative privileges to remotely execute arbitrary commands on the server. It is also vulnerable to a cross-site request forgery vulnerability that allows creating new administrative users.
Recommendations For versions prior to 1.8.007, update to version 1.8.007 or later to resolve the issue. As a temporary workaround, consider restricting administrative privileges to minimize the risk of exploitation. Restrict access to sensitive areas of the application to prevent cross-site request forgery attacks.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

MGASA-2014-0221

Affected Products

Egroupware