Vulnerabilities > Open Xchange > OX APP Suite > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-08 CVE-2023-29049 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
The "upsell" widget at the portal page could be abused to inject arbitrary script code.
network
low complexity
open-xchange CWE-79
6.1
2024-01-08 CVE-2023-29052 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.6
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly.
network
low complexity
open-xchange CWE-79
5.4
2024-01-08 CVE-2023-41710 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
User-defined script code could be stored for a upsell related shop URL.
network
low complexity
open-xchange CWE-79
5.4
2023-05-29 CVE-2023-24598 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24599 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24600 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24601 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
network
low complexity
open-xchange CWE-79
6.1
2023-05-29 CVE-2023-24602 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
network
low complexity
open-xchange CWE-79
6.1
2023-05-29 CVE-2023-24603 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.
network
low complexity
open-xchange
6.5
2023-05-29 CVE-2023-24604 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of header data.
network
low complexity
open-xchange
4.3