Plaintext Storage of a Password Affecting egroupware/egroupware package, versions <23.1.20231122


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-EGROUPWAREEGROUPWARE-6037698
  • published27 Oct 2023
  • disclosed26 Oct 2023
  • creditLuca Di Giuseppe, Antonio Papa, Stefano Scipioni, Fabio Minarelli, Massimiliano Brolli

Introduced: 26 Oct 2023

CVE-2023-38328  (opens in a new tab)
CWE-256  (opens in a new tab)

How to fix?

Upgrade egroupware/egroupware to version 23.1.20231122 or higher.

Overview

egroupware/egroupware is a library that extends a classic groupware with an integrated CRM-system, a secure file-server and Collabora Online Office.

Affected versions of this package are vulnerable to Plaintext Storage of a Password via the setup/manageheader.php panel. An attacker can read a cleartext database password by exploiting this vulnerability.

Note:

This is only exploitable if the attacker has authenticated remote administrator credentials.

CVSS Scores

version 3.1