Appsuite
by Open-Xchange
CVEs (213)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41707 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related… | ||
| CVE-2023-41706 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing… | ||
| CVE-2023-41705 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is… | ||
| CVE-2023-26428 | Med | 0.42 | 6.5 | 0.01 | Jun 20, 2023 | Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not… | ||
| CVE-2020-28943 | Med | 0.42 | 6.5 | 0.01 | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows SSRF via a snippet. | ||
| CVE-2021-23927 | Med | 0.42 | 6.4 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request. | ||
| CVE-2020-8544 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows SSRF. | ||
| CVE-2020-8541 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows XXE attacks. | ||
| CVE-2018-12609 | Med | 0.42 | 6.5 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery. | ||
| CVE-2018-9998 | Med | 0.42 | 6.5 | 0.02 | Jul 5, 2018 | Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitive information via the folder parameter in an "all" action… | ||
| CVE-2025-59025 | Med | 0.40 | 6.1 | 0.00 | Nov 27, 2025 | Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known | ||
| CVE-2024-23192 | Med | 0.40 | 6.1 | 0.01 | Apr 8, 2024 | RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or successfully luring users to compromised accounts. Attackers could perform malicious API requests or extract information from… | ||
| CVE-2023-41703 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2024 | User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are… | ||
| CVE-2023-29043 | Med | 0.40 | 6.1 | 0.00 | Nov 2, 2023 | Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when… | ||
| CVE-2022-43697 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob. | ||
| CVE-2022-37310 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI. | ||
| CVE-2022-37309 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name. | ||
| CVE-2022-37308 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages. | ||
| CVE-2022-37307 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature. | ||
| CVE-2022-31469 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI. |
- risk 0.42cvss 6.5epss 0.01
Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related…
- risk 0.42cvss 6.5epss 0.01
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing…
- risk 0.42cvss 6.5epss 0.01
Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is…
- risk 0.42cvss 6.5epss 0.01
Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not…
- risk 0.42cvss 6.5epss 0.01
OX App Suite 7.10.4 and earlier allows SSRF via a snippet.
- risk 0.42cvss 6.4epss 0.01
OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.3 allows SSRF.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.3 allows XXE attacks.
- risk 0.42cvss 6.5epss 0.01
OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
- risk 0.42cvss 6.5epss 0.02
Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitive information via the folder parameter in an "all" action…
- risk 0.40cvss 6.1epss 0.00
Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known
- risk 0.40cvss 6.1epss 0.01
RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or successfully luring users to compromised accounts. Attackers could perform malicious API requests or extract information from…
- risk 0.40cvss 6.1epss 0.01
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are…
- risk 0.40cvss 6.1epss 0.00
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when…
- risk 0.40cvss 6.1epss 0.00
OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
Page 3 of 11