Vulnerabilities > Open Xchange > Open Xchange Appsuite

DATE CVE VULNERABILITY TITLE RISK
2023-11-02 CVE-2023-29043 Cross-site Scripting vulnerability in Open-Xchange Appsuite
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document.
network
low complexity
open-xchange CWE-79
6.1
2023-11-02 CVE-2023-29044 Cross-site Scripting vulnerability in Open-Xchange Appsuite
Documents operations could be manipulated to contain invalid data types, possibly script code.
network
low complexity
open-xchange CWE-79
5.4
2023-11-02 CVE-2023-29045 Cross-site Scripting vulnerability in Open-Xchange Appsuite
Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code.
network
low complexity
open-xchange CWE-79
5.4
2023-11-02 CVE-2023-29046 Resource Exhaustion vulnerability in Open-Xchange Appsuite
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged.
network
low complexity
open-xchange CWE-400
4.3
2023-11-02 CVE-2023-29047 SQL Injection vulnerability in Open-Xchange Appsuite
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements.
low complexity
open-xchange CWE-89
7.3
2022-12-26 CVE-2022-29852 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
network
low complexity
open-xchange CWE-79
5.4
2022-12-26 CVE-2022-29853 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
network
low complexity
open-xchange CWE-79
5.4
2022-12-26 CVE-2022-37309 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
network
low complexity
open-xchange CWE-79
6.1
2022-12-26 CVE-2022-37310 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
network
low complexity
open-xchange CWE-79
6.1
2022-12-26 CVE-2022-37308 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
network
low complexity
open-xchange CWE-79
6.1