CVE-2016-4046
- EPSS 0.18%
- Published 15.12.2016 06:59:09
- Last modified 12.04.2025 10:46:40
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and po...
CVE-2016-4045
- EPSS 0.21%
- Published 15.12.2016 06:59:08
- Last modified 12.04.2025 10:46:40
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of ...
CVE-2016-4027
- EPSS 0.22%
- Published 15.12.2016 06:59:06
- Last modified 12.04.2025 10:46:40
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev10. App Suite frontend offers to control whether a user wants to store cookies that exceed the session duration. This functionality is useful when logging in from clients with reduc...
CVE-2016-4026
- EPSS 0.21%
- Published 15.12.2016 06:59:04
- Last modified 12.04.2025 10:46:40
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The content sanitizer component has an issue with filtering malicious content in case invalid HTML code is provided. In such cases the filter will output a unsanitized represent...
CVE-2016-3174
- EPSS 0.2%
- Published 15.12.2016 06:59:03
- Last modified 12.04.2025 10:46:40
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be provided as redirection target. Users can be tricked t...
CVE-2016-3173
- EPSS 0.24%
- Published 15.12.2016 06:59:02
- Last modified 12.04.2025 10:46:40
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The aria-label parameter of tiles at the Portal can be used to inject script code. Those labels use the name of the file (e.g. an image) which gets displayed at the portal applic...
CVE-2016-2840
- EPSS 0.34%
- Published 15.12.2016 06:59:01
- Last modified 12.04.2025 10:46:40
An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The "session" parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can ...
CVE-2015-5375
- EPSS 0.36%
- Published 28.09.2015 16:59:08
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in unspecified dialogs for printing content in the Front End in Open-Xchange Server 6 and OX App Suite before 6.22.8-rev8, 6.22.9 before 6.22.9-rev15m, 7.x before 7.6.1-rev25, and 7.6.2 before 7.6.2-rev20 allo...
- EPSS 0.07%
- Published 17.02.2015 15:59:01
- Last modified 12.04.2025 10:46:40
Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to...
CVE-2014-8993
- EPSS 0.26%
- Published 07.01.2015 18:59:01
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev40, 7.6.0 before 7.6.0-rev32, and 7.6.1 before 7.6.1-rev11 allows remote attackers to inject arbitrary web script or HTML via a crafted XHTML file w...