Vulnerability Details CVE-2022-29851
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-29851
-
cpe:2.3:a:open-xchange:ox_app_suite:-
-
cpe:2.3:a:open-xchange:ox_app_suite:7.10.5
-
cpe:2.3:a:open-xchange:ox_app_suite:7.10.6