Vulnerability Description
EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Egroupware | Egroupware | < 23.1.20240624 |
Related Weaknesses (CWE)
References
- https://github.com/EGroupware/egroupware/commit/553829d30cc2ccdc0e5a8c5a0e16fa03Patch
- https://github.com/EGroupware/egroupware/compare/23.1.20240430...23.1.20240624Patch
- https://github.com/EGroupware/egroupware/releases/tag/23.1.20240624Release Notes
- https://help.egroupware.org/t/egroupware-maintenance-security-release-23-1-20240Release Notes
- https://syss.deNot Applicable
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-047.t
- https://www.syss.de/pentest-blog/sql-injection-schwachstelle-in-egroupware-syss-
- https://github.com/EGroupware/egroupware/commit/553829d30cc2ccdc0e5a8c5a0e16fa03Patch
- https://github.com/EGroupware/egroupware/compare/23.1.20240430...23.1.20240624Patch
- https://github.com/EGroupware/egroupware/releases/tag/23.1.20240624Release Notes
- https://help.egroupware.org/t/egroupware-maintenance-security-release-23-1-20240Release Notes
- https://syss.deNot Applicable
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-047.t
- https://www.syss.de/pentest-blog/sql-injection-schwachstelle-in-egroupware-syss-
FAQ
What is CVE-2024-40614?
CVE-2024-40614 is a vulnerability with a CVSS score of 9.8 (CRITICAL). EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users f...
How severe is CVE-2024-40614?
CVE-2024-40614 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-40614?
Check the references section above for vendor advisories and patch information. Affected products include: Egroupware Egroupware.