NA

CVE-2023-41704

Published: 12/02/2024 Updated: 16/02/2024

Vulnerability Summary

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> OXAS-ADV-2023-0007: OX App Suite Security Advisory <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Martin ...