CVE-2017-14920: Egroupware

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.

Affected products

  • Egroupware Egroupware: up to and including 16.1.20170703

Published 2017-09-30. Last modified 2026-06-17.