Vulnerabilities > Open Xchange > Open Xchange Appsuite > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-02 CVE-2023-26452 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-26453 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to cache an image could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-26454 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-26455 Improper Authentication vulnerability in Open-Xchange Appsuite
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer.
local
low complexity
open-xchange CWE-287
7.8
2023-11-02 CVE-2023-29047 SQL Injection vulnerability in Open-Xchange Appsuite
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements.
low complexity
open-xchange CWE-89
7.3
2020-01-06 CVE-2019-16716 Incorrect Default Permissions vulnerability in Open-Xchange Appsuite
OX App Suite through 7.10.2 has Incorrect Access Control.
8.5
2019-06-17 CVE-2019-7158 Unspecified vulnerability in Open-Xchange Appsuite
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
network
low complexity
open-xchange
7.5
2019-05-23 CVE-2017-5212 Improper Access Control vulnerability in Open-Xchange Appsuite 7.8.3
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.
network
low complexity
open-xchange CWE-284
7.5
2019-05-23 CVE-2017-17060 Permission Issues vulnerability in Open-Xchange Appsuite
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.
network
low complexity
open-xchange CWE-275
7.5
2019-05-22 CVE-2017-5863 Improper Access Control vulnerability in Open-Xchange Appsuite
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
network
low complexity
open-xchange CWE-284
7.5