Vulnerabilities > Open Xchange > OX APP Suite

DATE CVE VULNERABILITY TITLE RISK
2021-11-22 CVE-2021-38377 Use of Insufficiently Random Values vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
network
low complexity
open-xchange CWE-330
6.1
2021-11-22 CVE-2021-38378 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
network
low complexity
open-xchange
4.3
2021-11-22 CVE-2021-33488 Improper Input Validation vulnerability in Open-Xchange OX APP Suite 7.10.5
chat in OX App Suite 7.10.5 has Improper Input Validation.
network
low complexity
open-xchange CWE-20
6.1
2021-11-22 CVE-2021-33489 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
network
low complexity
open-xchange CWE-79
6.1
2021-11-22 CVE-2021-33490 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
network
low complexity
open-xchange CWE-79
6.1