CVEs (157)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Jun 16, 2018 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 before 7.8.3-rev5, and 7.8.4 before 7.8.4-rev4 allows remote attackers to...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Jun 16, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafte...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Jun 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Jun 16, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Jun 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information ab...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Jun 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Apr 10, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto c...Show more |
1Open Xchange 2Open Xchange Appsuite Open Xchange ServerMay 13, 2026 Jun 8, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21. |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file exists or not. Attacker...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as profile pictures. In case their XML structure contains iframes and script code, that code may get executed when calling the...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when calling the related cov...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within hyperlinks at HTML E-Mails is not getting correctly sanitized when using base64 encoded "data" resources. This allows an attacker...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within SVG files is maintained when opening such files "in browser" based on our Mail or Drive app. In case of "a" tags, this may includ...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code can be injected to contact names. When adding those contacts to a group, the script code gets executed in the context of the user which...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user's name to JS code makes that code execute when selecting that user's "Templates" folder from OX Documents settings. This requires t...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment's location, will be pres...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev14. Adding images from external sources to HTML editors by drag&drop can potentially lead to script code execution in the context of the active user. T...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Custom messages can be shown at the login screen to notify external users about issues with sharing links. This mechanism can be abused to inject a...Show more |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requeste...Show more |