Vendor CVEs
Open-Xchange
All CVEs
304 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-2840 | Med | 0.40 | 6.1 | 0.02 | Dec 15, 2016 | An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The "session" parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can be executed within a trusted… | ||
| CVE-2021-33493 | Med | 0.39 | 6.0 | 0.00 | Nov 22, 2021 | The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format. | ||
| CVE-2018-5755 | Med | 0.39 | 5.5 | 0.08 | Jun 16, 2018 | Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 before 7.8.3-rev5, and 7.8.4 before 7.8.4-rev4 allows remote attackers to read arbitrary files via a full pathname in a formula in a… | ||
| CVE-2026-40205 | Med | 0.38 | 5.9 | 0.00 | Aug 28, 2026 | An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation… | ||
| CVE-2018-5754 | Med | 0.38 | 5.4 | 0.03 | Jun 16, 2018 | Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the… | ||
| CVE-2016-4046 | Med | 0.38 | 5.8 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending… | ||
| CVE-2026-27855 | Med | 0.37 | 6.8 | 0.00 | Mar 27, 2026 | Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as… | ||
| CVE-2023-26441 | Med | 0.37 | 5.7 | 0.00 | Aug 2, 2023 | Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are… | ||
| CVE-2023-26455 | Med | 0.36 | 5.6 | 0.00 | Nov 2, 2023 | RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated… | ||
| CVE-2023-26443 | Med | 0.36 | 5.5 | 0.01 | Aug 2, 2023 | Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly… | ||
| CVE-2016-6848 | Med | 0.36 | 5.5 | 0.00 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a… | ||
| CVE-2025-59026 | Med | 0.35 | 5.4 | 0.00 | Nov 27, 2025 | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch… | ||
| CVE-2025-30190 | Med | 0.35 | 5.4 | 0.00 | Nov 27, 2025 | Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No… | ||
| CVE-2025-30186 | Med | 0.35 | 5.4 | 0.00 | Nov 27, 2025 | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch… | ||
| CVE-2025-30191 | Med | 0.35 | 5.4 | 0.00 | Oct 31, 2025 | Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the… | ||
| CVE-2024-25582 | Med | 0.35 | 5.4 | 0.00 | Aug 19, 2024 | Module savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers could perform malicious API requests or extract information from the users account. Exploiting this vulnerability requires temporary access to an account or… | ||
| CVE-2024-23191 | Med | 0.35 | 5.4 | 0.01 | Apr 8, 2024 | Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to… | ||
| CVE-2024-23190 | Med | 0.35 | 5.4 | 0.01 | Apr 8, 2024 | Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously… | ||
| CVE-2024-23189 | Med | 0.35 | 5.4 | 0.01 | Apr 8, 2024 | Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to the users account, access to another account within the same context or an successful… | ||
| CVE-2023-41708 | Med | 0.35 | 5.4 | 0.00 | Feb 12, 2024 | References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now… | ||
| CVE-2023-41710 | Med | 0.35 | 5.4 | 0.00 | Jan 8, 2024 | User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added… | ||
| CVE-2023-29052 | Med | 0.35 | 5.4 | 0.00 | Jan 8, 2024 | Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added… | ||
| CVE-2023-29049 | Med | 0.35 | 5.4 | 0.01 | Jan 8, 2024 | The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a… | ||
| CVE-2023-29045 | Med | 0.35 | 5.4 | 0.00 | Nov 2, 2023 | Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged… | ||
| CVE-2023-29044 | Med | 0.35 | 5.4 | 0.00 | Nov 2, 2023 | Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating… | ||
| CVE-2023-26456 | Med | 0.35 | 5.4 | 0.00 | Nov 2, 2023 | Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to… | ||
| CVE-2023-26450 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2023 | The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit… | ||
| CVE-2023-26449 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2023 | The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit… | ||
| CVE-2023-26448 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2023 | Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface… | ||
| CVE-2023-26447 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2023 | The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking… | ||
| CVE-2023-26446 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2023 | The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit… | ||
| CVE-2023-26445 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2023 | Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the… | ||
| CVE-2022-29853 | Med | 0.35 | 5.4 | 0.00 | Dec 26, 2022 | OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message. | ||
| CVE-2022-29852 | Med | 0.35 | 5.4 | 0.00 | Dec 26, 2022 | OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked. | ||
| CVE-2022-37313 | Med | 0.35 | 5.3 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record. | ||
| CVE-2022-37312 | Med | 0.35 | 5.3 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet. | ||
| CVE-2022-37311 | Med | 0.35 | 5.3 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet. | ||
| CVE-2022-23099 | Med | 0.35 | 5.4 | 0.01 | Jul 27, 2022 | OX App Suite through 7.10.6 allows XSS by forcing block-wise read. | ||
| CVE-2021-44211 | Med | 0.35 | 5.4 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature. | ||
| CVE-2021-38376 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call. | ||
| CVE-2021-38374 | Med | 0.35 | 5.4 | 0.01 | Nov 22, 2021 | OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL. | ||
| CVE-2021-26699 | Med | 0.35 | 5.4 | 0.02 | Jul 22, 2021 | OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used. | ||
| CVE-2020-24700 | Med | 0.35 | 5.4 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring. | ||
| CVE-2020-12646 | Med | 0.35 | 5.4 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. | ||
| CVE-2020-8542 | Med | 0.35 | 5.4 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows XSS. | ||
| CVE-2019-14225 | Med | 0.35 | 5.4 | 0.01 | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows SSRF. | ||
| CVE-2019-11522 | Med | 0.35 | 5.4 | 0.01 | Aug 20, 2019 | OX App Suite 7.10.0 to 7.10.2 allows XSS. | ||
| CVE-2017-13668 | Med | 0.35 | 5.4 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-17061 | Med | 0.35 | 5.4 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-8341 | Med | 0.35 | 5.3 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. |
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The "session" parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can be executed within a trusted…
- risk 0.39cvss 6.0epss 0.00
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
- risk 0.39cvss 5.5epss 0.08
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 before 7.8.3-rev5, and 7.8.4 before 7.8.4-rev4 allows remote attackers to read arbitrary files via a full pathname in a formula in a…
- risk 0.38cvss 5.9epss 0.00
An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation…
- risk 0.38cvss 5.4epss 0.03
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the…
- risk 0.38cvss 5.8epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending…
- risk 0.37cvss 6.8epss 0.00
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as…
- risk 0.37cvss 5.7epss 0.00
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are…
- risk 0.36cvss 5.6epss 0.00
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated…
- risk 0.36cvss 5.5epss 0.01
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a…
- risk 0.35cvss 5.4epss 0.00
Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch…
- risk 0.35cvss 5.4epss 0.00
Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No…
- risk 0.35cvss 5.4epss 0.00
Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch…
- risk 0.35cvss 5.4epss 0.00
Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the…
- risk 0.35cvss 5.4epss 0.00
Module savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers could perform malicious API requests or extract information from the users account. Exploiting this vulnerability requires temporary access to an account or…
- risk 0.35cvss 5.4epss 0.01
Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to…
- risk 0.35cvss 5.4epss 0.01
Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously…
- risk 0.35cvss 5.4epss 0.01
Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to the users account, access to another account within the same context or an successful…
- risk 0.35cvss 5.4epss 0.00
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now…
- risk 0.35cvss 5.4epss 0.00
User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…
- risk 0.35cvss 5.4epss 0.00
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…
- risk 0.35cvss 5.4epss 0.01
The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a…
- risk 0.35cvss 5.4epss 0.00
Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged…
- risk 0.35cvss 5.4epss 0.00
Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating…
- risk 0.35cvss 5.4epss 0.00
Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to…
- risk 0.35cvss 5.4epss 0.01
The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…
- risk 0.35cvss 5.4epss 0.01
The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…
- risk 0.35cvss 5.4epss 0.01
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface…
- risk 0.35cvss 5.4epss 0.01
The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking…
- risk 0.35cvss 5.4epss 0.01
The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…
- risk 0.35cvss 5.4epss 0.01
Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the…
- risk 0.35cvss 5.4epss 0.00
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
- risk 0.35cvss 5.4epss 0.00
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.6 allows XSS by forcing block-wise read.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
- risk 0.35cvss 5.3epss 0.01
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
- risk 0.35cvss 5.4epss 0.02
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.3 allows XSS.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.0 to 7.10.2 allows XSS.
- risk 0.35cvss 5.4epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.35cvss 5.4epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.35cvss 5.3epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
Page 4 of 7