5.4
CVE-2023-29052
- EPSS 0.44%
- Veröffentlicht 08.01.2024 09:15:20
- Zuletzt bearbeitet 04.11.2025 19:15:42
- Erkennungen
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open-xchange ≫ Ox App Suite Version 7.10.6 Update -
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev01
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev02
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev03
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev04
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev05
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev06
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev07
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev08
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev09
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev10
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev11
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev12
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev13
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev14
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev15
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev16
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev17
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev18
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev19
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev20
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev21
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev22
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev23
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev24
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev25
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev26
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev27
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev28
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev29
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev30
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev31
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev32
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev33
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev34
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.44% | 0.346 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| security@open-xchange.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0006.json
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf
http://seclists.org/fulldisclosure/2024/Jan/4