Vulnerabilities > Open Xchange > OX APP Suite

DATE CVE VULNERABILITY TITLE RISK
2024-01-08 CVE-2023-29048 OS Command Injection vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user.
network
low complexity
open-xchange CWE-78
8.8
2024-01-08 CVE-2023-29049 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
The "upsell" widget at the portal page could be abused to inject arbitrary script code.
network
low complexity
open-xchange CWE-79
6.1
2024-01-08 CVE-2023-29050 Injection vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6/8.16
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy.
network
low complexity
open-xchange CWE-74
critical
9.6
2024-01-08 CVE-2023-29051 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6/8.17
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API.
network
low complexity
open-xchange
8.1
2024-01-08 CVE-2023-29052 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.6
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly.
network
low complexity
open-xchange CWE-79
5.4
2024-01-08 CVE-2023-41710 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
User-defined script code could be stored for a upsell related shop URL.
network
low complexity
open-xchange CWE-79
5.4
2023-05-29 CVE-2023-24598 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24599 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24600 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24601 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
network
low complexity
open-xchange CWE-79
6.1