Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rvxj-7f72-mhrx | EGroupware has SQL Injection in Nextmatch Filter Processing |
Thu, 19 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:egroupware:egroupware:*:*:*:*:community:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Egroupware
Egroupware egroupware |
|
| Vendors & Products |
Egroupware
Egroupware egroupware |
Wed, 28 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.20260113, specifically in the `Nextmatch` filter processing. The flaw allows authenticated attackers to inject arbitrary SQL commands into the `WHERE` clause of database queries. This is achieved by exploiting a PHP type juggling issue where JSON decoding converts numeric strings into integers, bypassing the `is_int()` security check used by the application. Versions 23.1.20260113 and 26.0.20260113 patch the vulnerability. | |
| Title | EGroupware has SQL Injection in Nextmatch Filter Processing | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-28T16:28:24.378Z
Reserved: 2026-01-07T05:19:12.920Z
Link: CVE-2026-22243
Updated: 2026-01-28T16:28:13.675Z
Status : Analyzed
Published: 2026-01-28T17:16:15.663
Modified: 2026-02-19T21:21:44.660
Link: CVE-2026-22243
No data.
OpenCVE Enrichment
Updated: 2026-04-18T01:45:33Z
Github GHSA