High severity7.1NVD Advisory· Published Aug 2, 2023· Updated Jun 17, 2026
CVE-2023-26440
CVE-2023-26440
Description
The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:open-xchange:open-xchange_appsuite_office:*:*:*:*:*:*:*:*Range: <8.11
- Range: 0
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2023/Aug/8nvdMailing ListThird Party Advisory
- software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdfnvdRelease Notes
- documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.jsonnvd
News mentions
0No linked articles in our index yet.