Improper Password Storage Vulnerability in eGroupWare by eGroupWare Team
CVE-2023-38328
4.9MEDIUM
What is CVE-2023-38328?
An improper password storage vulnerability exists in eGroupWare 17.1.20190111, specifically within the setup panel located at setup/manageheader.php. This flaw allows authenticated remote attackers with administrator credentials to access database passwords stored in cleartext. Such exposure poses significant risks, potentially allowing unauthorized access to sensitive data and system compromise.