Vulnerabilities > Open Xchange
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-08 | CVE-2023-29052 | Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.6 Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. | 5.4 |
2024-01-08 | CVE-2023-41710 | Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 User-defined script code could be stored for a upsell related shop URL. | 5.4 |
2023-11-02 | CVE-2023-26452 | SQL Injection vulnerability in Open-Xchange Appsuite Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. | 8.8 |
2023-11-02 | CVE-2023-26453 | SQL Injection vulnerability in Open-Xchange Appsuite Requests to cache an image could be abused to include SQL queries that would be executed unchecked. | 8.8 |
2023-11-02 | CVE-2023-26454 | SQL Injection vulnerability in Open-Xchange Appsuite Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. | 8.8 |
2023-11-02 | CVE-2023-26455 | Improper Authentication vulnerability in Open-Xchange Appsuite RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. | 7.8 |
2023-11-02 | CVE-2023-26456 | Cross-site Scripting vulnerability in Open-Xchange OX Guard Users were able to set an arbitrary "product name" for OX Guard. | 5.4 |
2023-11-02 | CVE-2023-29043 | Cross-site Scripting vulnerability in Open-Xchange Appsuite Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. | 6.1 |
2023-11-02 | CVE-2023-29044 | Cross-site Scripting vulnerability in Open-Xchange Appsuite Documents operations could be manipulated to contain invalid data types, possibly script code. | 5.4 |
2023-11-02 | CVE-2023-29045 | Cross-site Scripting vulnerability in Open-Xchange Appsuite Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. | 5.4 |