VYPR
Medium severity6.1NVD Advisory· Published May 3, 2021· Updated Jun 17, 2026

CVE-2020-28945

CVE-2020-28945

Description

OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://onerror=Function.constructor, in a Notes item.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Open-Xchange/Appsuitellm-create2 versions
    <=7.10.4+ 1 more
    • (no CPE)range: <=7.10.4
    • cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:*range: <=7.10.4
  • OX/App Suitedescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.