Vulnerabilities > Open Xchange > OX APP Suite > 8.14

DATE CVE VULNERABILITY TITLE RISK
2024-05-06 CVE-2024-23186 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite
E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices.
network
low complexity
open-xchange CWE-79
6.1
2024-05-06 CVE-2024-23187 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite
Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option.
network
low complexity
open-xchange CWE-79
6.1
2024-05-06 CVE-2024-23193 Session Fixation vulnerability in Open-Xchange OX APP Suite
E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account.
network
high complexity
open-xchange CWE-384
5.3