Ox App Suite
by Open-Xchange
CVEs (94)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12611 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Directory Traversal. | ||
| CVE-2021-33493 | Med | 0.39 | 6.0 | 0.00 | Nov 22, 2021 | The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format. | ||
| CVE-2023-41710 | Med | 0.35 | 5.4 | 0.00 | Jan 8, 2024 | User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added… | ||
| CVE-2023-29052 | Med | 0.35 | 5.4 | 0.00 | Jan 8, 2024 | Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added… | ||
| CVE-2023-29049 | Med | 0.35 | 5.4 | 0.01 | Jan 8, 2024 | The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a… | ||
| CVE-2022-29853 | Med | 0.35 | 5.4 | 0.00 | Dec 26, 2022 | OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message. | ||
| CVE-2022-29852 | Med | 0.35 | 5.4 | 0.00 | Dec 26, 2022 | OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked. | ||
| CVE-2022-37313 | Med | 0.35 | 5.3 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record. | ||
| CVE-2022-23099 | Med | 0.35 | 5.4 | 0.01 | Jul 27, 2022 | OX App Suite through 7.10.6 allows XSS by forcing block-wise read. | ||
| CVE-2021-44211 | Med | 0.35 | 5.4 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature. | ||
| CVE-2021-38376 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call. | ||
| CVE-2021-38374 | Med | 0.35 | 5.4 | 0.01 | Nov 22, 2021 | OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL. | ||
| CVE-2021-26699 | Med | 0.35 | 5.4 | 0.02 | Jul 22, 2021 | OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used. | ||
| CVE-2020-12646 | Med | 0.35 | 5.4 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. | ||
| CVE-2020-8542 | Med | 0.35 | 5.4 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows XSS. | ||
| CVE-2019-14225 | Med | 0.35 | 5.4 | 0.01 | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows SSRF. | ||
| CVE-2017-8341 | Med | 0.35 | 5.3 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. | ||
| CVE-2018-12610 | Med | 0.35 | 5.3 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Information Exposure. | ||
| CVE-2024-23193 | Med | 0.34 | 5.3 | 0.01 | May 6, 2024 | E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared.… | ||
| CVE-2023-24597 | Med | 0.34 | 5.3 | 0.01 | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing. |
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.8.4 and earlier allows Directory Traversal.
- risk 0.39cvss 6.0epss 0.00
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
- risk 0.35cvss 5.4epss 0.00
User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…
- risk 0.35cvss 5.4epss 0.00
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…
- risk 0.35cvss 5.4epss 0.01
The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a…
- risk 0.35cvss 5.4epss 0.00
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
- risk 0.35cvss 5.4epss 0.00
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.6 allows XSS by forcing block-wise read.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
- risk 0.35cvss 5.4epss 0.02
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.3 allows XSS.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
- risk 0.35cvss 5.3epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
- risk 0.35cvss 5.3epss 0.01
OX App Suite 7.8.4 and earlier allows Information Exposure.
- risk 0.34cvss 5.3epss 0.01
E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared.…
- risk 0.34cvss 5.3epss 0.01
OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.
Page 4 of 5