cve/2024/CVE-2024-40614.md
2024-07-25 21:25:12 +00:00

740 B

CVE-2024-40614

Description

EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.

POC

Reference

Github

No PoCs found on GitHub currently.