Vulnerabilities > Open Xchange > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-22 CVE-2021-38376 Improper Authentication vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
network
low complexity
open-xchange CWE-287
5.3
2021-11-22 CVE-2021-38377 Use of Insufficiently Random Values vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
network
low complexity
open-xchange CWE-330
6.1
2021-11-22 CVE-2021-38378 Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
network
low complexity
open-xchange
4.3
2021-11-22 CVE-2021-33488 Improper Input Validation vulnerability in Open-Xchange OX APP Suite 7.10.5
chat in OX App Suite 7.10.5 has Improper Input Validation.
network
low complexity
open-xchange CWE-20
6.1
2021-11-22 CVE-2021-33489 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
network
low complexity
open-xchange CWE-79
6.1
2021-11-22 CVE-2021-33490 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
network
low complexity
open-xchange CWE-79
6.1
2021-07-30 CVE-2021-28093 Inadequate Encryption Strength vulnerability in Open-Xchange Documents 7.10.5/7.8.3
OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.
network
low complexity
open-xchange CWE-326
6.5
2021-07-30 CVE-2021-28094 Inadequate Encryption Strength vulnerability in Open-Xchange Documents 7.10.5/7.8.3
OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.
network
low complexity
open-xchange CWE-326
6.5
2021-07-30 CVE-2021-28095 Inadequate Encryption Strength vulnerability in Open-Xchange Documents 7.10.5/7.8.3
OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.
network
high complexity
open-xchange CWE-326
4.8
2021-07-22 CVE-2021-26698 Cross-site Scripting vulnerability in Open-Xchange Appsuite 7.10.3/7.10.4
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and the dl parameter is used.
network
low complexity
open-xchange CWE-79
6.1