VYPR

Appsuite

by Open-Xchange

CVEs (213)

  • CVE-2023-26452HigNov 2, 2023
    risk 0.49cvss 7.6epss 0.00

    Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by…

  • CVE-2023-26451HigAug 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result,…

  • CVE-2023-26439HigAug 2, 2023
    risk 0.49cvss 7.6epss 0.00

    The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users…

  • CVE-2020-8543HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.02

    OX App Suite through 7.10.3 has Improper Input Validation.

  • CVE-2014-5236HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.04

    Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument…

  • CVE-2019-7159HigJun 18, 2019
    risk 0.49cvss 7.5epss 0.02

    OX App Suite 7.10.1 and earlier allows Information Exposure.

  • CVE-2017-5211HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

  • CVE-2017-12884HigMay 10, 2019
    risk 0.49cvss 7.5epss 0.01

    OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure.

  • CVE-2016-3174HigDec 15, 2016
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be provided as redirection target. Users can be tricked to follow a link to a…

  • CVE-2023-41704HigFeb 12, 2024
    risk 0.46cvss 7.1epss 0.01

    Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing…

  • CVE-2023-26440HigAug 2, 2023
    risk 0.46cvss 7.1epss 0.00

    The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have…

  • CVE-2023-26436HigJun 20, 2023
    risk 0.46cvss 7.1epss 0.01

    Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary code could be injected that is being…

  • CVE-2018-5753MedJun 16, 2018
    risk 0.46cvss 6.5epss 0.08

    The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode characters in the "personal part" of a (1) From or (2)…

  • CVE-2018-5751MedJun 16, 2018
    risk 0.46cvss 6.5epss 0.09

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information about external guest users via vectors related to the…

  • CVE-2017-17062MedJun 16, 2018
    risk 0.46cvss 6.5epss 0.04

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege management.

  • CVE-2019-16716MedJan 6, 2020
    risk 0.43cvss 6.6epss 0.02

    OX App Suite through 7.10.2 has Incorrect Access Control.

  • CVE-2016-5740MedDec 15, 2016
    risk 0.43cvss 6.1epss 0.04

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment's location, will be presented to the user at the E-Mail App, depending on the…

  • CVE-2024-23188MedMay 6, 2024
    risk 0.42cvss 6.5epss 0.01

    Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is required for the vulnerability to trigger. Attackers could perform malicious API requests or extract information…

  • CVE-2024-23187MedMay 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious API requests or extract information from the users account. Exploiting the vulnerability requires user…

  • CVE-2024-23186MedMay 6, 2024
    risk 0.42cvss 6.5epss 0.01

    E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch…

Page 2 of 11