VYPR

Appsuite

by Open-Xchange

CVEs (213)

  • CVE-2023-41708MedFeb 12, 2024
    risk 0.35cvss 5.4epss 0.00

    References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now…

  • CVE-2023-41710MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…

  • CVE-2023-29052MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…

  • CVE-2023-29049MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.01

    The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a…

  • CVE-2023-29045MedNov 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged…

  • CVE-2023-29044MedNov 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating…

  • CVE-2023-26450MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…

  • CVE-2023-26449MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…

  • CVE-2023-26448MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface…

  • CVE-2023-26447MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking…

  • CVE-2023-26446MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…

  • CVE-2023-26445MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the…

  • CVE-2022-29853MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.00

    OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.

  • CVE-2022-29852MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.00

    OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.

  • CVE-2022-37313MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

  • CVE-2022-37312MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.

  • CVE-2022-37311MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.

  • CVE-2022-23099MedJul 27, 2022
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.6 allows XSS by forcing block-wise read.

  • CVE-2021-44211MedMar 28, 2022
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.

  • CVE-2021-38376MedNov 22, 2021
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.

Page 7 of 11