OX App Suite
by OX App Suite
CVEs (77)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-23933 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL. | ||
| CVE-2021-23932 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename. | ||
| CVE-2021-23931 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an inline binary file. | ||
| CVE-2021-23930 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile. | ||
| CVE-2021-23929 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI. | ||
| CVE-2021-23928 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string. | ||
| CVE-2020-24701 | Med | 0.40 | 6.1 | 0.07 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI). | ||
| CVE-2019-16717 | Med | 0.40 | 6.1 | 0.02 | Jan 6, 2020 | OX App Suite through 7.10.2 has XSS. | ||
| CVE-2019-14227 | Med | 0.40 | 6.1 | 0.01 | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows XSS. | ||
| CVE-2021-33493 | Med | 0.39 | 6.0 | 0.00 | Nov 22, 2021 | The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format. | ||
| CVE-2022-29853 | Med | 0.35 | 5.4 | 0.00 | Dec 26, 2022 | OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message. | ||
| CVE-2022-29852 | Med | 0.35 | 5.4 | 0.00 | Dec 26, 2022 | OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked. | ||
| CVE-2022-37313 | Med | 0.35 | 5.3 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record. | ||
| CVE-2022-37312 | Med | 0.35 | 5.3 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet. | ||
| CVE-2022-37311 | Med | 0.35 | 5.3 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet. | ||
| CVE-2021-38374 | Med | 0.35 | 5.4 | 0.01 | Nov 22, 2021 | OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL. | ||
| CVE-2021-26699 | Med | 0.35 | 5.4 | 0.02 | Jul 22, 2021 | OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used. | ||
| CVE-2020-24700 | Med | 0.35 | 5.4 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring. | ||
| CVE-2020-12646 | Med | 0.35 | 5.4 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. | ||
| CVE-2020-8542 | Med | 0.35 | 5.4 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows XSS. |
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via an inline binary file.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.
- risk 0.40cvss 6.1epss 0.07
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
- risk 0.40cvss 6.1epss 0.02
OX App Suite through 7.10.2 has XSS.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.1 and 7.10.2 allows XSS.
- risk 0.39cvss 6.0epss 0.00
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
- risk 0.35cvss 5.4epss 0.00
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
- risk 0.35cvss 5.4epss 0.00
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
- risk 0.35cvss 5.4epss 0.02
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.3 allows XSS.
Page 3 of 4