EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupwareApiEtemplateWidgetNextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Egroupware | Egroupware | * | 23.1.20240624 (excluding) |