Open-xchange

Open-xchange Appsuite

157 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 02.11.2023 14:15:11
  • Zuletzt bearbeitet 21.11.2024 07:56:26

Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read ...

  • EPSS 0.06%
  • Veröffentlicht 02.11.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:29

Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not expose...

  • EPSS 0.06%
  • Veröffentlicht 02.11.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:29

Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by ...

  • EPSS 0.06%
  • Veröffentlicht 02.11.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:29

Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networ...

  • EPSS 0.03%
  • Veröffentlicht 02.11.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:30

RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. T...

  • EPSS 0.73%
  • Veröffentlicht 26.12.2022 04:15:10
  • Zuletzt bearbeitet 14.04.2025 19:15:30

OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.

  • EPSS 0.73%
  • Veröffentlicht 26.12.2022 04:15:10
  • Zuletzt bearbeitet 14.04.2025 19:15:30

OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.

Exploit
  • EPSS 0.69%
  • Veröffentlicht 26.12.2022 04:15:10
  • Zuletzt bearbeitet 14.04.2025 15:15:19

OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.

Exploit
  • EPSS 0.69%
  • Veröffentlicht 26.12.2022 04:15:10
  • Zuletzt bearbeitet 14.04.2025 15:15:19

OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.

Exploit
  • EPSS 0.69%
  • Veröffentlicht 26.12.2022 03:15:11
  • Zuletzt bearbeitet 14.04.2025 15:15:18

OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.