6.1
CVSSv3

CVE-2016-5740

Published: 15/12/2016 Updated: 19/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in Open-Xchange OX App Suite prior to 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment's location, will be presented to the user at the E-Mail App, depending on the invitation workflow. This code gets executed within the context of the user's current session. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).

Vulnerable Product Search on Vulmon Subscribe to Product

open-xchange open-xchange appsuite

Exploits

Product: OX App Suite Vendor: OX Software GmbH Internal reference: 46484 (Bug ID) Vulnerability type: Cross Site Scripting (CWE-80) Vulnerable version: 782 and earlier Vulnerable component: frontend Report confidence: Confirmed Solution status: Fixed by Vendor Fixed version: 762-rev46, 763-rev14, 780-rev29, 781-rev16, 782-rev5 Vendor n ...
Open-Xchange App Suite versions 782 and below suffer from multiple cross site scripting vulnerabilities ...