Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42147 | An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web script or HTML into the "user" HTTP/GET parameter, which reflects its input without sanitization. |
| Link | Providers |
|---|---|
| https://www.gruppotim.it/it/footer/red-team.html |
|
Thu, 11 Sep 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:egroupware:egroupware:17.1.20190111:*:*:*:community:*:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Fri, 11 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web script or HTML into the "user" HTTP/GET parameter, which reflects its input without sanitization. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-15T19:55:53.646Z
Reserved: 2023-07-14T00:00:00.000Z
Link: CVE-2023-38329
Updated: 2025-07-14T16:45:22.311Z
Status : Analyzed
Published: 2025-07-11T15:15:23.893
Modified: 2025-09-11T20:49:38.580
Link: CVE-2023-38329
No data.
OpenCVE Enrichment
Updated: 2025-07-16T21:35:18Z
EUVD