Vulnerabilities > Open Xchange > OX APP Suite > 7.10.5

DATE CVE VULNERABILITY TITLE RISK
2024-01-08 CVE-2023-29048 OS Command Injection vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user.
network
low complexity
open-xchange CWE-78
8.8
2024-01-08 CVE-2023-29049 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
The "upsell" widget at the portal page could be abused to inject arbitrary script code.
network
low complexity
open-xchange CWE-79
6.1
2024-01-08 CVE-2023-29050 Injection vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6/8.16
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy.
network
low complexity
open-xchange CWE-74
critical
9.6
2024-01-08 CVE-2023-29051 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6/8.17
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API.
network
low complexity
open-xchange
8.1
2024-01-08 CVE-2023-41710 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
User-defined script code could be stored for a upsell related shop URL.
network
low complexity
open-xchange CWE-79
5.4
2023-05-29 CVE-2023-24598 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24599 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24600 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24601 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
network
low complexity
open-xchange CWE-79
6.1
2023-05-29 CVE-2023-24602 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
network
low complexity
open-xchange CWE-79
6.1