Vulnerabilities > Open Xchange > OX APP Suite > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-22 CVE-2021-38376 Improper Authentication vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
network
low complexity
open-xchange CWE-287
5.0
2021-11-22 CVE-2021-38377 Use of Insufficiently Random Values vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
4.3
2021-11-22 CVE-2021-38378 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
network
low complexity
open-xchange
4.0
2021-11-22 CVE-2021-33488 Improper Input Validation vulnerability in Open-Xchange OX APP Suite 7.10.5
chat in OX App Suite 7.10.5 has Improper Input Validation.
5.8
2021-11-22 CVE-2021-33489 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
4.3
2021-11-22 CVE-2021-33490 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
4.3