VYPR

Appsuite

by Open-Xchange

CVEs (213)

  • CVE-2019-16717MedJan 6, 2020
    risk 0.40cvss 6.1epss 0.02

    OX App Suite through 7.10.2 has XSS.

  • CVE-2013-7486MedJan 2, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from…

  • CVE-2013-7485MedJan 2, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message.…

  • CVE-2013-6242MedJan 2, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the…

  • CVE-2019-14227MedOct 14, 2019
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.1 and 7.10.2 allows XSS.

  • CVE-2017-5213MedMay 23, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-15030MedMay 23, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-9808MedMay 22, 2019
    risk 0.40cvss 6.1epss 0.01

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-5864MedMay 22, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-12885MedMay 10, 2019
    risk 0.40cvss 6.1epss 0.01

    OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2018-12611MedJan 30, 2019
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.8.4 and earlier allows Directory Traversal.

  • CVE-2017-6913MedSep 18, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.

  • CVE-2018-9997MedJul 5, 2018
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute…

  • CVE-2015-1588MedJun 8, 2017
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.

  • CVE-2016-6846MedMar 29, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0…

  • CVE-2016-6850MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as profile pictures. In case their XML structure contains iframes and script code, that code may get executed when calling the related picture URL or viewing the related person's image…

  • CVE-2016-6847MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when calling the related cover URL. Malicious script code can be executed within a…

  • CVE-2016-6845MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within hyperlinks at HTML E-Mails is not getting correctly sanitized when using base64 encoded "data" resources. This allows an attacker to provide hyperlinks that may execute script code instead…

  • CVE-2016-6844MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within SVG files is maintained when opening such files "in browser" based on our Mail or Drive app. In case of "a" tags, this may include link targets with base64 encoded "data" references.…

  • CVE-2016-6843MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code can be injected to contact names. When adding those contacts to a group, the script code gets executed in the context of the user which creates or changes the group by using autocomplete. In most…

Page 5 of 11