← Back

CVE-2023-26446

nvd nist
Published: Aug 2, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize the user-controllable clientID parameter. No publicly available exploits are known.

Affected (2)

1 product
Open Xchange Appsuite Frontend
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Up to 7.10.6
From 8.10 to 8.12

Timeline

No history available yet.