PT-2025-29231 · Unknown · Egroupware

Published

2025-07-11

·

Updated

2025-07-11

·

CVE-2023-38327

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: eGroupWare version 17.1.20190111
Description: A user enumeration issue exists in eGroupWare. An unauthenticated remote attacker can enumerate users of web applications based on server response via the /calendar/freebusy.php API endpoint.
Recommendations: Update to a newer version of eGroupWare. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2023-38327

Affected Products

Egroupware