Vulnerabilities > Open Xchange > OX APP Suite > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-05-06 CVE-2024-23186 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite
E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices.
network
low complexity
open-xchange CWE-79
6.1
2024-05-06 CVE-2024-23187 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite
Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option.
network
low complexity
open-xchange CWE-79
6.1
2024-05-06 CVE-2024-23193 Session Fixation vulnerability in Open-Xchange OX APP Suite
E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account.
network
high complexity
open-xchange CWE-384
5.3
2024-01-08 CVE-2023-29049 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
The "upsell" widget at the portal page could be abused to inject arbitrary script code.
network
low complexity
open-xchange CWE-79
6.1
2024-01-08 CVE-2023-29052 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.6
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly.
network
low complexity
open-xchange CWE-79
5.4
2024-01-08 CVE-2023-41710 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
User-defined script code could be stored for a upsell related shop URL.
network
low complexity
open-xchange CWE-79
5.4
2023-05-29 CVE-2023-24598 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24599 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24600 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
network
low complexity
open-xchange
4.3
2023-05-29 CVE-2023-24601 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
network
low complexity
open-xchange CWE-79
6.1