Vulnerability Details CVE-2018-5754
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.9%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2018-5754
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:6.20.7
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:6.22.0
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:6.22.1
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:6.22.3
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:6.22.4
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.0.1
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.0.2
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.0
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.1
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.2
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.0
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.1
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.1
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.2
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.3
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.8.0
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.8.1
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.8.2
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.8.3
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.8.4