VYPR

Ox App Suite

by Open-Xchange

CVEs (94)

  • CVE-2018-12611MedJan 30, 2019
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.8.4 and earlier allows Directory Traversal.

  • CVE-2021-33493MedNov 22, 2021
    risk 0.39cvss 6.0epss 0.00

    The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

  • CVE-2023-41710MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…

  • CVE-2023-29052MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…

  • CVE-2023-29049MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.01

    The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a…

  • CVE-2022-29853MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.00

    OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.

  • CVE-2022-29852MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.00

    OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.

  • CVE-2022-37313MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

  • CVE-2022-23099MedJul 27, 2022
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.6 allows XSS by forcing block-wise read.

  • CVE-2021-44211MedMar 28, 2022
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.

  • CVE-2021-38376MedNov 22, 2021
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.

  • CVE-2021-38374MedNov 22, 2021
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.

  • CVE-2021-26699MedJul 22, 2021
    risk 0.35cvss 5.4epss 0.02

    OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.

  • CVE-2020-12646MedAug 31, 2020
    risk 0.35cvss 5.4epss 0.01

    OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.

  • CVE-2020-8542MedJun 16, 2020
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.3 allows XSS.

  • CVE-2019-14225MedOct 14, 2019
    risk 0.35cvss 5.4epss 0.01

    OX App Suite 7.10.1 and 7.10.2 allows SSRF.

  • CVE-2017-8341MedMay 22, 2019
    risk 0.35cvss 5.3epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

  • CVE-2018-12610MedJan 30, 2019
    risk 0.35cvss 5.3epss 0.01

    OX App Suite 7.8.4 and earlier allows Information Exposure.

  • CVE-2024-23193MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.01

    E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared.…

  • CVE-2023-24597MedMay 29, 2023
    risk 0.34cvss 5.3epss 0.01

    OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.

Page 4 of 5