Appsuite
by Open-Xchange
CVEs (213)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26699 | Med | 0.35 | 5.4 | 0.02 | Jul 22, 2021 | OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used. | ||
| CVE-2020-24700 | Med | 0.35 | 5.4 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring. | ||
| CVE-2020-12646 | Med | 0.35 | 5.4 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. | ||
| CVE-2020-8542 | Med | 0.35 | 5.4 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows XSS. | ||
| CVE-2019-14225 | Med | 0.35 | 5.4 | 0.01 | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows SSRF. | ||
| CVE-2019-11522 | Med | 0.35 | 5.4 | 0.01 | Aug 20, 2019 | OX App Suite 7.10.0 to 7.10.2 allows XSS. | ||
| CVE-2017-13668 | Med | 0.35 | 5.4 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-17061 | Med | 0.35 | 5.4 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-8341 | Med | 0.35 | 5.3 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. | ||
| CVE-2017-9809 | Med | 0.35 | 5.3 | 0.01 | May 22, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure. | ||
| CVE-2018-13104 | Med | 0.35 | 5.4 | 0.01 | Mar 21, 2019 | OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID) | ||
| CVE-2018-13103 | Med | 0.35 | 5.4 | 0.01 | Mar 21, 2019 | OX App Suite 7.8.4 and earlier allows SSRF. | ||
| CVE-2018-12610 | Med | 0.35 | 5.3 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Information Exposure. | ||
| CVE-2014-2078 | Med | 0.35 | 5.3 | 0.01 | Apr 10, 2018 | The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto configuration for external accounts. | ||
| CVE-2016-3173 | Med | 0.35 | 5.4 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The aria-label parameter of tiles at the Portal can be used to inject script code. Those labels use the name of the file (e.g. an image) which gets displayed at the portal application. Using script code at… | ||
| CVE-2024-23193 | Med | 0.34 | 5.3 | 0.01 | May 6, 2024 | E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared.… | ||
| CVE-2023-29047 | Med | 0.34 | 5.3 | 0.00 | Nov 2, 2023 | Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content… | ||
| CVE-2023-26435 | Med | 0.33 | 5.0 | 0.01 | Jun 20, 2023 | It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system… | ||
| CVE-2023-26431 | Med | 0.33 | 5.0 | 0.01 | Jun 20, 2023 | IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight… | ||
| CVE-2020-15002 | Med | 0.33 | 5.0 | 0.02 | Oct 23, 2020 | OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. |
- risk 0.35cvss 5.4epss 0.02
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.3 allows XSS.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.0 to 7.10.2 allows XSS.
- risk 0.35cvss 5.4epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.35cvss 5.4epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.35cvss 5.3epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
- risk 0.35cvss 5.3epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.8.4 and earlier allows SSRF.
- risk 0.35cvss 5.3epss 0.01
OX App Suite 7.8.4 and earlier allows Information Exposure.
- risk 0.35cvss 5.3epss 0.01
The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto configuration for external accounts.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The aria-label parameter of tiles at the Portal can be used to inject script code. Those labels use the name of the file (e.g. an image) which gets displayed at the portal application. Using script code at…
- risk 0.34cvss 5.3epss 0.01
E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared.…
- risk 0.34cvss 5.3epss 0.00
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content…
- risk 0.33cvss 5.0epss 0.01
It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system…
- risk 0.33cvss 5.0epss 0.01
IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight…
- risk 0.33cvss 5.0epss 0.02
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
Page 8 of 11