Medium severity6.1NVD Advisory· Published Dec 15, 2016· Updated Jun 17, 2026
CVE-2016-6847
CVE-2016-6847
Description
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when calling the related cover URL. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Affected products
2cpe:2.3:a:open-xchange:open-xchange_appsuite:*:rev4:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:open-xchange:open-xchange_appsuite:*:rev4:*:*:*:*:*:*range: <=7.8.2
- (no CPE)range: <7.8.2-rev8
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/93457nvdThird Party AdvisoryVDB Entry
- software.open-xchange.com/OX6/6.22/doc/Release_Notes_for_Patch_Release_3522_7.8.2_2016-08-29.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.