Vulnerabilities > Open Xchange

DATE CVE VULNERABILITY TITLE RISK
2024-01-08 CVE-2023-29052 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.6
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly.
network
low complexity
open-xchange CWE-79
5.4
2024-01-08 CVE-2023-41710 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
User-defined script code could be stored for a upsell related shop URL.
network
low complexity
open-xchange CWE-79
5.4
2023-11-02 CVE-2023-26452 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-26453 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to cache an image could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-26454 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-26455 Improper Authentication vulnerability in Open-Xchange Appsuite
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer.
local
low complexity
open-xchange CWE-287
7.8
2023-11-02 CVE-2023-26456 Cross-site Scripting vulnerability in Open-Xchange OX Guard
Users were able to set an arbitrary "product name" for OX Guard.
network
low complexity
open-xchange CWE-79
5.4
2023-11-02 CVE-2023-29043 Cross-site Scripting vulnerability in Open-Xchange Appsuite
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document.
network
low complexity
open-xchange CWE-79
6.1
2023-11-02 CVE-2023-29044 Cross-site Scripting vulnerability in Open-Xchange Appsuite
Documents operations could be manipulated to contain invalid data types, possibly script code.
network
low complexity
open-xchange CWE-79
5.4
2023-11-02 CVE-2023-29045 Cross-site Scripting vulnerability in Open-Xchange Appsuite
Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code.
network
low complexity
open-xchange CWE-79
5.4