Improper Password Storage Vulnerability in eGroupWare by eGroupWare Team
CVE-2023-38328

4.9MEDIUM

Key Information:

Vendor

Egroupware

Vendor
CVE Published:
26 October 2023

What is CVE-2023-38328?

An improper password storage vulnerability exists in eGroupWare 17.1.20190111, specifically within the setup panel located at setup/manageheader.php. This flaw allows authenticated remote attackers with administrator credentials to access database passwords stored in cleartext. Such exposure poses significant risks, potentially allowing unauthorized access to sensitive data and system compromise.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.