Vulnerability Details CVE-2021-37402
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.7%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-37402
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.3
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.4