eGroupWare
cpe:2.3:a:egroupware:egroupware:*:*:*:*:*:*:*
- 17.1.20190111
A user enumeration vulnerability has been identified in eGroupWare version 17.1.20190111. This vulnerability resides in the calendar/freebusy.php file and allows unauthenticated remote attackers to enumerate users of web applications based on the server's response.
Exploitation of this vulnerability allows for user enumeration, which could be used as a preliminary step in a targeted attack, such as phishing or credential stuffing.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.