← Back

CVE-2023-26456

nvd nist
Published: Nov 2, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to trigger persistent code execution, allowing an attacker to build a foothold. Sanitization is in place for product names now. No publicly available exploits are known.

Affected (5)

1 product
Ox Guard
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Before 2.10.7
Version 2.10.7
Version 2.10.7 rev4
Version 2.10.7 rev5
Version 2.10.7 rev6

Timeline

No history available yet.