Vulnerabilities > Open Xchange > OX APP Suite > 7.10.6

DATE CVE VULNERABILITY TITLE RISK
2022-10-25 CVE-2022-31468 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
network
low complexity
open-xchange CWE-79
6.1
2022-10-25 CVE-2022-29851 OS Command Injection vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
network
low complexity
open-xchange CWE-78
critical
9.8
2022-07-27 CVE-2022-24406 Use of Insufficiently Random Values vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
network
low complexity
open-xchange CWE-330
6.5