High severity7.6NVD Advisory· Published Aug 2, 2023· Updated Jun 17, 2026
CVE-2023-26439
CVE-2023-26439
Description
The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users cached data. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:open-xchange:open-xchange_appsuite_office:*:*:*:*:*:*:*:*Range: <8.11
- Range: 0
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2023/Aug/8nvdMailing ListThird Party Advisory
- software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdfnvdRelease Notes
- documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.jsonnvd
News mentions
0No linked articles in our index yet.