Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.
{
"cpe": "cpe:2.3:a:egroupware:egroupware:*:*:*:*:community:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "16.1.20170703"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}