Releases179
Frequency6 days 5 hours
Last Release
Stars19
tine groupware main repository

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)