6.1
CVSSv3

CVE-2023-29049

Published: 08/01/2024 Updated: 12/01/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a trusted domain. User input for this widget is now sanitized to avoid malicious content the be processed. No publicly available exploits are known.

Vulnerable Product Search on Vulmon Subscribe to Product

open-xchange ox app suite 7.10.6

open-xchange ox app suite

Mailing Lists

Dear subscribers, We're sharing our latest advisory with you and like to thank everyone who contributed in finding and solving those vulnerabilities Feel free to join our bug bounty programs for OX AppSuite, Dovecot and PowerDNS at YesWeHack This advisory has also been published at documentationopen-xchangecom/security/advisories/ ...