Ox App Suite
by Open-Xchange
CVEs (86)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-44208 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat. | ||
| CVE-2021-38377 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results. | ||
| CVE-2021-38375 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message. | ||
| CVE-2021-33495 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite 7.10.5 allows XSS via an OX Chat system message. | ||
| CVE-2021-33494 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering. | ||
| CVE-2021-33492 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite 7.10.5 allows XSS via an OX Chat room name. | ||
| CVE-2021-33490 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature. | ||
| CVE-2021-33489 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file. | ||
| CVE-2021-33488 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook. | ||
| CVE-2021-37403 | Med | 0.40 | 6.1 | 0.01 | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used. | ||
| CVE-2021-37402 | Med | 0.40 | 6.1 | 0.01 | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled. | ||
| CVE-2019-16717 | Med | 0.40 | 6.1 | 0.02 | Jan 6, 2020 | OX App Suite through 7.10.2 has XSS. | ||
| CVE-2019-14227 | Med | 0.40 | 6.1 | 0.01 | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows XSS. | ||
| CVE-2017-5213 | Med | 0.40 | 6.1 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-15030 | Med | 0.40 | 6.1 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-5864 | Med | 0.40 | 6.1 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2018-12611 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Directory Traversal. | ||
| CVE-2021-33493 | Med | 0.39 | 6.0 | 0.00 | Nov 22, 2021 | The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format. | ||
| CVE-2023-41710 | Med | 0.35 | 5.4 | 0.00 | Jan 8, 2024 | User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added… | ||
| CVE-2023-29052 | Med | 0.35 | 5.4 | 0.00 | Jan 8, 2024 | Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added… |
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.5 allows XSS via an OX Chat system message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.5 allows XSS via an OX Chat room name.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
- risk 0.40cvss 6.1epss 0.01
chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.
- risk 0.40cvss 6.1epss 0.02
OX App Suite through 7.10.2 has XSS.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.1 and 7.10.2 allows XSS.
- risk 0.40cvss 6.1epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.8.4 and earlier allows Directory Traversal.
- risk 0.39cvss 6.0epss 0.00
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
- risk 0.35cvss 5.4epss 0.00
User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…
- risk 0.35cvss 5.4epss 0.00
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…
Page 3 of 5