VYPR

Ox App Suite

by Open-Xchange

CVEs (86)

  • CVE-2021-44208MedMar 28, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.

  • CVE-2021-38377MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.

  • CVE-2021-38375MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.

  • CVE-2021-33495MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.5 allows XSS via an OX Chat system message.

  • CVE-2021-33494MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.

  • CVE-2021-33492MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.5 allows XSS via an OX Chat room name.

  • CVE-2021-33490MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

  • CVE-2021-33489MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.

  • CVE-2021-33488MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.

  • CVE-2021-37403MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.

  • CVE-2021-37402MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.

  • CVE-2019-16717MedJan 6, 2020
    risk 0.40cvss 6.1epss 0.02

    OX App Suite through 7.10.2 has XSS.

  • CVE-2019-14227MedOct 14, 2019
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.1 and 7.10.2 allows XSS.

  • CVE-2017-5213MedMay 23, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-15030MedMay 23, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-5864MedMay 22, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2018-12611MedJan 30, 2019
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.8.4 and earlier allows Directory Traversal.

  • CVE-2021-33493MedNov 22, 2021
    risk 0.39cvss 6.0epss 0.00

    The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

  • CVE-2023-41710MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…

  • CVE-2023-29052MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…