|
Description
|
|
ReactionIS has discovered a vulnerability in Group-Office, which can be exploited by malicious users to conduct SQL injection attacks.
Input passed via the "sort" parameter to modules/calendar/json.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injection arbitrary SQL code.
The vulnerability is confirmed in version 4.0.89. Other versions may also be affected.
|