CVE-2023-38328: Egroupware

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of under setup/manageheader.php, which allows authenticated remote attackers with administrator credentials to read a cleartext database password.

Affected products

Published 2023-10-26. Last modified 2026-06-17.