Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open-xchange ox app suite vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-44209
OX App Suite up to and including 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-44210
OX App Suite up to and including 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.
Open-xchange Ox App Suite
5.4
CVSSv3
CVE-2021-44211
OX App Suite up to and including 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
Open-xchange Ox App Suite
6.5
CVSSv3
CVE-2021-33491
OX App Suite up to and including 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-33494
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
Open-xchange Ox App Suite 7.10.5
5.4
CVSSv3
CVE-2021-38374
OX App Suite through up to and including 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
Open-xchange Ox App Suite
5.3
CVSSv3
CVE-2021-38376
OX App Suite up to and including 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
Open-xchange Ox App Suite
4.3
CVSSv3
CVE-2021-38378
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-38375
OX App Suite up to and including 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
Open-xchange Ox App Suite
6.1
CVSSv3
CVE-2021-38377
OX App Suite up to and including 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
Open-xchange Ox App Suite
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »