Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open-xchange ox app suite vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2022-23101
OX App Suite up to and including 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
Open-xchange Ox App Suite
5.4
CVSSv3
CVE-2021-38374
OX App Suite through up to and including 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-38375
OX App Suite up to and including 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
Open-xchange Ox App Suite
5.3
CVSSv3
CVE-2021-38376
OX App Suite up to and including 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-38377
OX App Suite up to and including 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
Open-xchange Ox App Suite
4.3
CVSSv3
CVE-2021-38378
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-33488
chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-33489
OX App Suite up to and including 7.10.5 allows XSS via JavaScript code in a shared XCF file.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-33490
OX App Suite up to and including 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
Open-xchange Ox App Suite
6.5
CVSSv3
CVE-2021-33491
OX App Suite up to and including 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
Open-xchange Ox App Suite
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »