{"id":"CVE-2017-14920","aliases":["GHSA-qfg7-wc25-r3j2"],"url":"https://o3.security/vulnerability/CVE-2017-14920","summary":"eGroupware Community Edition Stored XSS vulnerability","details":"Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.","published":"2017-09-30T01:29:01.867Z","modified":"2026-08-07T15:00:03.246502Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"egroupware/egroupware","fixedVersion":"16.1.20170922"}],"fix":{"url":"https://github.com/EGroupware/egroupware/commit/0ececf8c78f1c3f9ba15465f53a682dd7d89529f","label":"EGroupware/egroupware@0ececf8"},"references":[{"type":"FIX","url":"http://openwall.com/lists/oss-security/2017/09/28/12"},{"type":"FIX","url":"https://github.com/EGroupware/egroupware/commit/0ececf8c78f1c3f9ba15465f53a682dd7d89529f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14920"},{"type":"PACKAGE","url":"https://github.com/EGroupware/egroupware"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:00:03.246502Z"}}