VYPR
Medium severity6.1NVD Advisory· Published Jan 2, 2020· Updated Jun 17, 2026

CVE-2013-6242

CVE-2013-6242

Description

Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the body of the email and the publication name were SPLIT from this CVE ID because they affect different sets of versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Open-Xchange (OX)/AppSuitedescription
  • Open-Xchange/Appsuitellm-fuzzy5 versions
    <6.22.3-rev5, <6.22.4-rev12+ 4 more
    • (no CPE)range: <6.22.3-rev5, <6.22.4-rev12
    • cpe:2.3:a:open-xchange:open-xchange_appsuite:6.22.3:*:*:*:*:*:*:*
    • cpe:2.3:a:open-xchange:open-xchange_appsuite:6.22.4:*:*:*:*:*:*:*
    • cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.