Medium severity6.5NVD Advisory· Published May 6, 2024· Updated Jun 17, 2026
CVE-2024-23187
CVE-2024-23187
Description
Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious API requests or extract information from the users account. Exploiting the vulnerability requires user interaction. Please deploy the provided updates and patch releases. CID replacement has been hardened to omit invalid identifiers. No publicly available exploits are known.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Open-Xchange GmbH/OX App Suitev5Range: 0
Patches
Vulnerability mechanics
References
3- seclists.org/fulldisclosure/2024/May/3nvdMailing ListThird Party Advisory
- documentation.open-xchange.com/appsuite/security/advisories/csaf/2024/oxas-adv-2024-0002.jsonnvdIssue TrackingVendor Advisory
- documentation.open-xchange.com/appsuite/releases/8.22/nvdRelease Notes
News mentions
0No linked articles in our index yet.