6.8
CVSSv2

CVE-2014-2987

Published: 26/10/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) prior to 1.1.20140505, EGroupware Community Edition prior to 1.8.007.20140506, and EGroupware prior to 14.1 beta allow remote malicious users to hijack the authentication of administrators for requests that (1) create an administrator user via an admin.uiaccounts.add_user action to index.php or (2) modify settings via the newsettings parameter in an admin.uiconfig.index action to index.php. NOTE: vector 2 can be used to execute arbitrary PHP code by leveraging CVE-2014-2988.

Vulnerable Product Search on Vulmon Subscribe to Product

egroupware egroupware

Exploits

Advisory ID: HTB23212 Product: EGroupware Vendor: wwwegroupwareorg/ Vulnerable Version(s): 18006 community edition and probably prior Tested Version: 18006 community edition Advisory Publication: April 23, 2014 [without technical details] Vendor Notification: April 23, 2014 Vendor Patch: May 6, 2014 Public Disclosure: May 14, 2014 ...
EGroupware version 18006 suffers from code execution and cross site request forgery vulnerabilities ...