OX App Suite up to and including 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
open-xchange open-xchange appsuite |
||
open-xchange open-xchange appsuite 7.10.5 |
||
open-xchange open-xchange appsuite 7.10.6 |