Open-xchange

Open-xchange Appsuite

157 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Published 02.11.2023 14:15:11
  • Last modified 21.11.2024 07:56:26

Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read ...

  • EPSS 0.06%
  • Published 02.11.2023 14:15:10
  • Last modified 21.11.2024 07:51:29

Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not expose...

  • EPSS 0.06%
  • Published 02.11.2023 14:15:10
  • Last modified 21.11.2024 07:51:29

Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by ...

  • EPSS 0.06%
  • Published 02.11.2023 14:15:10
  • Last modified 21.11.2024 07:51:29

Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networ...

  • EPSS 0.03%
  • Published 02.11.2023 14:15:10
  • Last modified 21.11.2024 07:51:30

RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. T...

  • EPSS 0.73%
  • Published 26.12.2022 04:15:10
  • Last modified 14.04.2025 19:15:30

OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.

  • EPSS 0.73%
  • Published 26.12.2022 04:15:10
  • Last modified 14.04.2025 19:15:30

OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.

Exploit
  • EPSS 0.69%
  • Published 26.12.2022 04:15:10
  • Last modified 14.04.2025 15:15:19

OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.

Exploit
  • EPSS 0.69%
  • Published 26.12.2022 04:15:10
  • Last modified 14.04.2025 15:15:19

OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.

Exploit
  • EPSS 0.69%
  • Published 26.12.2022 03:15:11
  • Last modified 14.04.2025 15:15:18

OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.