Vulnerabilities > Open Xchange > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-22 CVE-2021-33491 Path Traversal vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
network
low complexity
open-xchange CWE-22
4.0
2021-11-22 CVE-2021-33492 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows XSS via an OX Chat room name.
4.3
2021-11-22 CVE-2021-33494 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
4.3
2021-11-22 CVE-2021-33495 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows XSS via an OX Chat system message.
4.3
2021-11-22 CVE-2021-38374 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
network
low complexity
open-xchange CWE-79
5.4
2021-11-22 CVE-2021-38375 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
4.3
2021-11-22 CVE-2021-38376 Improper Authentication vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
network
low complexity
open-xchange CWE-287
5.0
2021-11-22 CVE-2021-38377 Use of Insufficiently Random Values vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
4.3
2021-11-22 CVE-2021-38378 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
network
low complexity
open-xchange
4.0
2021-11-22 CVE-2021-33488 Improper Input Validation vulnerability in Open-Xchange OX APP Suite 7.10.5
chat in OX App Suite 7.10.5 has Improper Input Validation.
5.8