Vulnerabilities > Open Xchange > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-02-12 CVE-2023-41703 Cross-site Scripting vulnerability in Open-Xchange Appsuite
User ID references at mentions in document comments were not correctly sanitized.
network
low complexity
open-xchange CWE-79
6.1
2024-02-12 CVE-2023-41704 Cross-site Scripting vulnerability in Open-Xchange Appsuite
Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine.
network
low complexity
open-xchange CWE-79
6.1
2024-02-12 CVE-2023-41705 Unspecified vulnerability in Open-Xchange Appsuite
Processing of user-defined DAV user-agent strings is not limited.
network
low complexity
open-xchange
6.5
2024-02-12 CVE-2023-41706 Unspecified vulnerability in Open-Xchange Appsuite
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached.
network
low complexity
open-xchange
6.5
2024-02-12 CVE-2023-41707 Unspecified vulnerability in Open-Xchange Appsuite
Processing of user-defined mail search expressions is not limited.
network
low complexity
open-xchange
6.5
2024-02-12 CVE-2023-41708 Cross-site Scripting vulnerability in Open-Xchange Appsuite
References to the "app loader" functionality could contain redirects to unexpected locations.
network
low complexity
open-xchange CWE-79
5.4
2024-01-08 CVE-2023-29049 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
The "upsell" widget at the portal page could be abused to inject arbitrary script code.
network
low complexity
open-xchange CWE-79
6.1
2024-01-08 CVE-2023-29052 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.6
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly.
network
low complexity
open-xchange CWE-79
5.4
2024-01-08 CVE-2023-41710 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
User-defined script code could be stored for a upsell related shop URL.
network
low complexity
open-xchange CWE-79
5.4
2023-11-02 CVE-2023-26456 Cross-site Scripting vulnerability in Open-Xchange OX Guard
Users were able to set an arbitrary "product name" for OX Guard.
network
low complexity
open-xchange CWE-79
5.4