Open-xchange

Ox App Suite

54 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Published 28.03.2022 01:15:07
  • Last modified 21.11.2024 06:30:35

OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.

Exploit
  • EPSS 0.25%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:16:56

OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.

Exploit
  • EPSS 0.3%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:16:56

OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.

Exploit
  • EPSS 0.27%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:16:56

OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.

Exploit
  • EPSS 0.34%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:16:56

OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.

Exploit
  • EPSS 0.38%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:16:55

OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.

Exploit
  • EPSS 0.3%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:08:56

OX App Suite 7.10.5 allows XSS via an OX Chat system message.

Exploit
  • EPSS 0.49%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:08:56

OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.

Exploit
  • EPSS 0.2%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:08:56

The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

Exploit
  • EPSS 0.49%
  • Published 22.11.2021 09:15:07
  • Last modified 21.11.2024 06:08:56

OX App Suite 7.10.5 allows XSS via an OX Chat room name.