NA

CVE-2023-41703

Published: 12/02/2024 Updated: 16/02/2024

Vulnerability Summary

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> OXAS-ADV-2023-0007: OX App Suite Security Advisory <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Martin ...