VYPR

Vendor CVEs

OX App Suite

All CVEs

68 total · sorted by risk
  • CVE-2022-29851CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.

  • CVE-2022-24405CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

  • CVE-2019-7158CriJun 17, 2019
    risk 0.64cvss 9.8epss 0.02

    OX App Suite 7.10.0 and earlier has Incorrect Access Control.

  • CVE-2019-14226HigOct 14, 2019
    risk 0.53cvss 8.1epss 0.01

    OX App Suite through 7.10.2 has Insecure Permissions.

  • CVE-2020-8543HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.02

    OX App Suite through 7.10.3 has Improper Input Validation.

  • CVE-2023-41706MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing…

  • CVE-2023-41705MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is…

  • CVE-2023-24603MedMay 29, 2023
    risk 0.42cvss 6.5epss 0.01

    OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.

  • CVE-2022-24406MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.

  • CVE-2021-33491MedNov 22, 2021
    risk 0.42cvss 6.5epss 0.02

    OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.

  • CVE-2020-8544MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.3 allows SSRF.

  • CVE-2018-12609MedJan 30, 2019
    risk 0.42cvss 6.5epss 0.01

    OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.

  • CVE-2023-24602MedMay 29, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.

  • CVE-2023-24601MedMay 29, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.

  • CVE-2022-43697MedApr 15, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.

  • CVE-2022-43696MedApr 15, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.

  • CVE-2022-37309MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.

  • CVE-2022-37308MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.

  • CVE-2022-37307MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.

  • CVE-2022-31469MedDec 26, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.

  • CVE-2022-23101MedJul 27, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.

  • CVE-2021-44212MedMar 28, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.

  • CVE-2021-44209MedMar 28, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.

  • CVE-2021-44208MedMar 28, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.

  • CVE-2021-38377MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.

  • CVE-2021-38375MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.

  • CVE-2021-33495MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.5 allows XSS via an OX Chat system message.

  • CVE-2021-33490MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

  • CVE-2021-33489MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.

  • CVE-2021-33488MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.

  • CVE-2021-37403MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.

  • CVE-2021-37402MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.

  • CVE-2021-31934MedApr 30, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.

  • CVE-2021-23935MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.

  • CVE-2021-23933MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.

  • CVE-2021-23932MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.

  • CVE-2021-23931MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via an inline binary file.

  • CVE-2021-23929MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI.

  • CVE-2021-23928MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.

  • CVE-2020-24701MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.07

    OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).

  • CVE-2019-16717MedJan 6, 2020
    risk 0.40cvss 6.1epss 0.02

    OX App Suite through 7.10.2 has XSS.

  • CVE-2019-14227MedOct 14, 2019
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.1 and 7.10.2 allows XSS.

  • CVE-2021-33493MedNov 22, 2021
    risk 0.39cvss 6.0epss 0.00

    The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

  • CVE-2022-29853MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.00

    OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.

  • CVE-2022-37312MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.

  • CVE-2022-37311MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.

  • CVE-2021-38374MedNov 22, 2021
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.

  • CVE-2021-26699MedJul 22, 2021
    risk 0.35cvss 5.4epss 0.02

    OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.

  • CVE-2020-24700MedJan 12, 2021
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

  • CVE-2020-12646MedAug 31, 2020
    risk 0.35cvss 5.4epss 0.01

    OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.

Page 1 of 2