SQL Injection Vulnerability in EGroupware Products by eGroupware
CVE-2011-4949

Currently unrated

Key Information:

Vendor

Egroupware

Vendor
CVE Published:
31 August 2012

What is CVE-2011-4949?

An SQL injection vulnerability exists within the EGroupware web application, specifically in the loaddetails.php script. This flaw permits remote attackers to manipulate the database by injecting arbitrary SQL commands through the 'id' parameter. Versions of the EGroupware Enterprise Line prior to 11.1.20110804-1 and the Community Edition earlier than 1.8.001.20110805 are affected, exposing them to potential data breaches and unauthorized data manipulation.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.