Vulnerabilities > Open Xchange > OX APP Suite > 7.10.5

DATE CVE VULNERABILITY TITLE RISK
2021-11-22 CVE-2021-33493 Code Injection vulnerability in Open-Xchange OX APP Suite 7.10.5
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
local
low complexity
open-xchange CWE-94
3.6
2021-11-22 CVE-2021-33494 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
4.3
2021-11-22 CVE-2021-33495 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows XSS via an OX Chat system message.
4.3
2021-11-22 CVE-2021-38374 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
network
low complexity
open-xchange CWE-79
5.4
2021-11-22 CVE-2021-38375 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
4.3
2021-11-22 CVE-2021-38376 Improper Authentication vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
network
low complexity
open-xchange CWE-287
5.0
2021-11-22 CVE-2021-38377 Use of Insufficiently Random Values vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
4.3
2021-11-22 CVE-2021-38378 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
network
low complexity
open-xchange
4.0
2021-11-22 CVE-2021-33488 Improper Input Validation vulnerability in Open-Xchange OX APP Suite 7.10.5
chat in OX App Suite 7.10.5 has Improper Input Validation.
5.8
2021-11-22 CVE-2021-33489 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
4.3