PT-2024-28943 · Unknown · Egroupware
Christian Zäske
·
Published
2024-07-07
·
Updated
2025-11-25
·
CVE-2024-40614
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EGroupware versions prior to 23.1.20240624
Description
The issue arises from the mishandling of an ORDER BY clause, leading to SQL injection by authenticated users when sorting Address Book or InfoLog. This specifically affects the "json.php?menuaction=EGroupwareApiEtemplateWidgetNextmatch::ajax get rows" endpoint, where the
sort.id parameter is vulnerable.Recommendations
For versions prior to 23.1.20240624, update to version 23.1.20240624 or later to resolve the issue. As a temporary workaround, consider restricting access to the "json.php?menuaction=EGroupwareApiEtemplateWidgetNextmatch::ajax get rows" endpoint to minimize the risk of exploitation. Additionally, avoid using the
sort.id parameter in the affected endpoint until the issue is resolved.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Egroupware