VYPR

Appsuite

by Open-Xchange

CVEs (213)

  • CVE-2016-6842MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user's name to JS code makes that code execute when selecting that user's "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code…

  • CVE-2016-5124MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev14. Adding images from external sources to HTML editors by drag&drop can potentially lead to script code execution in the context of the active user. To exploit this, a user needs to be tricked to use an image…

  • CVE-2016-4045MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of the user. Malicious script…

  • CVE-2016-4026MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The content sanitizer component has an issue with filtering malicious content in case invalid HTML code is provided. In such cases the filter will output a unsanitized representation of the content.…

  • CVE-2016-2840MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The "session" parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can be executed within a trusted…

  • CVE-2018-5755MedJun 16, 2018
    risk 0.39cvss 5.5epss 0.08

    Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 before 7.8.3-rev5, and 7.8.4 before 7.8.4-rev4 allows remote attackers to read arbitrary files via a full pathname in a formula in a…

  • CVE-2018-5754MedJun 16, 2018
    risk 0.38cvss 5.4epss 0.03

    Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the…

  • CVE-2016-4046MedDec 15, 2016
    risk 0.38cvss 5.8epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending…

  • CVE-2023-26441MedAug 2, 2023
    risk 0.37cvss 5.7epss 0.00

    Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are…

  • CVE-2023-26455MedNov 2, 2023
    risk 0.36cvss 5.6epss 0.00

    RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated…

  • CVE-2023-26443MedAug 2, 2023
    risk 0.36cvss 5.5epss 0.01

    Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly…

  • CVE-2016-6848MedDec 15, 2016
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a…

  • CVE-2025-59026MedNov 27, 2025
    risk 0.35cvss 5.4epss 0.00

    Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch…

  • CVE-2025-30190MedNov 27, 2025
    risk 0.35cvss 5.4epss 0.00

    Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No…

  • CVE-2025-30186MedNov 27, 2025
    risk 0.35cvss 5.4epss 0.00

    Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch…

  • CVE-2025-30191MedOct 31, 2025
    risk 0.35cvss 5.4epss 0.00

    Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the…

  • CVE-2024-25582MedAug 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Module savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers could perform malicious API requests or extract information from the users account. Exploiting this vulnerability requires temporary access to an account or…

  • CVE-2024-23191MedApr 8, 2024
    risk 0.35cvss 5.4epss 0.01

    Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to…

  • CVE-2024-23190MedApr 8, 2024
    risk 0.35cvss 5.4epss 0.01

    Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously…

  • CVE-2024-23189MedApr 8, 2024
    risk 0.35cvss 5.4epss 0.01

    Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to the users account, access to another account within the same context or an successful…

Page 6 of 11