Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open-xchange appsuite vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2016-4045
An issue exists in Open-Xchange OX App Suite prior to 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of the user. Malicious script code can ...
Open-xchange Open-xchange Appsuite
6.1
CVSSv3
CVE-2016-5740
An issue exists in Open-Xchange OX App Suite prior to 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment's location, will be presented to the user at the E-Mail App, depending on the invitat...
Open-xchange Open-xchange Appsuite
1 EDB exploit
6.1
CVSSv3
CVE-2016-5124
An issue exists in Open-Xchange OX App Suite prior to 7.8.1-rev14. Adding images from external sources to HTML editors by drag&drop can potentially lead to script code execution in the context of the active user. To exploit this, a user needs to be tricked to use an image fro...
Open-xchange Open-xchange Appsuite
6.1
CVSSv3
CVE-2016-6843
An issue exists in Open-Xchange OX App Suite prior to 7.8.2-rev8. Script code can be injected to contact names. When adding those contacts to a group, the script code gets executed in the context of the user which creates or changes the group by using autocomplete. In most cases ...
Open-xchange Open-xchange Appsuite
6.1
CVSSv3
CVE-2016-6844
An issue exists in Open-Xchange OX App Suite prior to 7.8.2-rev8. Script code within SVG files is maintained when opening such files "in browser" based on our Mail or Drive app. In case of "a" tags, this may include link targets with base64 encoded "data&...
Open-xchange Open-xchange Appsuite
6.1
CVSSv3
CVE-2016-6845
An issue exists in Open-Xchange OX App Suite prior to 7.8.2-rev8. Script code within hyperlinks at HTML E-Mails is not getting correctly sanitized when using base64 encoded "data" resources. This allows an malicious user to provide hyperlinks that may execute script cod...
Open-xchange Open-xchange Appsuite
5.8
CVSSv3
CVE-2016-4046
An issue exists in Open-Xchange OX App Suite prior to 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending on the r...
Open-xchange Open-xchange Appsuite
5.5
CVSSv3
CVE-2023-26441
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are ac...
Open-xchange Open-xchange Appsuite Office
5.5
CVSSv3
CVE-2018-5755
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite prior to 7.6.3-rev3, 7.8.x prior to 7.8.2-rev4, 7.8.3 prior to 7.8.3-rev5, and 7.8.4 prior to 7.8.4-rev4 allows remote malicious users to read arbitrary files via a full pathname in a...
Open-xchange Open-xchange Appsuite 7.8.4
Open-xchange Open-xchange Appsuite 7.8.3
Open-xchange Open-xchange Appsuite 7.8.2
Open-xchange Open-xchange Appsuite 7.8.0
Open-xchange Open-xchange Appsuite
1 EDB exploit
5.5
CVSSv3
CVE-2016-6848
An issue exists in Open-Xchange OX App Suite prior to 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a t...
Open-xchange Open-xchange Appsuite
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »