PT-2024-28943 · Unknown · Egroupware

Christian Zäske

·

Published

2024-07-07

·

Updated

2025-11-25

·

CVE-2024-40614

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EGroupware versions prior to 23.1.20240624
Description The issue arises from the mishandling of an ORDER BY clause, leading to SQL injection by authenticated users when sorting Address Book or InfoLog. This specifically affects the "json.php?menuaction=EGroupwareApiEtemplateWidgetNextmatch::ajax get rows" endpoint, where the sort.id parameter is vulnerable.
Recommendations For versions prior to 23.1.20240624, update to version 23.1.20240624 or later to resolve the issue. As a temporary workaround, consider restricting access to the "json.php?menuaction=EGroupwareApiEtemplateWidgetNextmatch::ajax get rows" endpoint to minimize the risk of exploitation. Additionally, avoid using the sort.id parameter in the affected endpoint until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-40614
GHSA-PHG7-8MM9-GJ88

Affected Products

Egroupware