VYPR

Appsuite

by Open-Xchange

CVEs (213)

  • CVE-2023-41707MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related…

  • CVE-2023-41706MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing…

  • CVE-2023-41705MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is…

  • CVE-2023-26428MedJun 20, 2023
    risk 0.42cvss 6.5epss 0.01

    Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not…

  • CVE-2020-28943MedApr 30, 2021
    risk 0.42cvss 6.5epss 0.01

    OX App Suite 7.10.4 and earlier allows SSRF via a snippet.

  • CVE-2021-23927MedJan 12, 2021
    risk 0.42cvss 6.4epss 0.01

    OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.

  • CVE-2020-8544MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.3 allows SSRF.

  • CVE-2020-8541MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.3 allows XXE attacks.

  • CVE-2018-12609MedJan 30, 2019
    risk 0.42cvss 6.5epss 0.01

    OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.

  • CVE-2018-9998MedJul 5, 2018
    risk 0.42cvss 6.5epss 0.02

    Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitive information via the folder parameter in an "all" action…

  • CVE-2025-59025MedNov 27, 2025
    risk 0.40cvss 6.1epss 0.00

    Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known

  • CVE-2024-23192MedApr 8, 2024
    risk 0.40cvss 6.1epss 0.01

    RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or successfully luring users to compromised accounts. Attackers could perform malicious API requests or extract information from…

  • CVE-2023-41703MedFeb 12, 2024
    risk 0.40cvss 6.1epss 0.01

    User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are…

  • CVE-2023-29043MedNov 2, 2023
    risk 0.40cvss 6.1epss 0.00

    Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when…

  • CVE-2022-43697MedApr 15, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.

  • CVE-2022-37310MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.

  • CVE-2022-37309MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.

  • CVE-2022-37308MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.

  • CVE-2022-37307MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.

  • CVE-2022-31469MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.

Page 3 of 11