漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
EGroupware has SQL Injection in Nextmatch Filter Processing
Vulnerability Description
EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.20260113, specifically in the `Nextmatch` filter processing. The flaw allows authenticated attackers to inject arbitrary SQL commands into the `WHERE` clause of database queries. This is achieved by exploiting a PHP type juggling issue where JSON decoding converts numeric strings into integers, bypassing the `is_int()` security check used by the application. Versions 23.1.20260113 and 26.0.20260113 patch the vulnerability.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
EGroupware SQL注入漏洞
Vulnerability Description
EGroupware是EGroupware公司的一个在线办公平台。 EGroupware 23.1.20260113之前版本和26.0.20260113之前版本存在SQL注入漏洞,该漏洞源于Nextmatch过滤器处理存在PHP类型混淆问题,可能导致SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A