CVE-2017-14920: Egroupware
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.
Affected products
- Egroupware Egroupware: up to and including 16.1.20170703
Published 2017-09-30. Last modified 2026-06-17.