CVE-2023-26429
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are known.
Affected (4)
Products: Open Xchange: Open Xchange Appsuite Backend
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.10.6 |
References (8)
Source: security@open-xchange.com
Third Party AdvisoryVDB Entry
Source: security@open-xchange.com
Mailing ListThird Party Advisory
Source: security@open-xchange.com
Source: security@open-xchange.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Timeline
No history available yet.