Vulnerabilities
Vulnerable Software
OX App Suite 7.8.4 and earlier allows SSRF.
CVSS Score
5.4
EPSS Score
0.001
Published
2019-03-21
OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)
CVSS Score
5.4
EPSS Score
0.002
Published
2019-03-21
OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
CVSS Score
6.5
EPSS Score
0.004
Published
2019-01-30
OX App Suite 7.8.4 and earlier allows Information Exposure.
CVSS Score
5.3
EPSS Score
0.003
Published
2019-01-30
OX App Suite 7.8.4 and earlier allows Directory Traversal.
CVSS Score
6.1
EPSS Score
0.005
Published
2019-01-30
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.
CVSS Score
5.4
EPSS Score
0.004
Published
2018-06-16
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev14. Adding images from external sources to HTML editors by drag&drop can potentially lead to script code execution in the context of the active user. To exploit this, a user needs to be tricked to use an image from a specially crafted website and add it to HTML editor areas of OX App Suite, for example E-Mail Compose or OX Text. This specific attack circumvents typical XSS filters and detection mechanisms since the code is not loaded from an external service but injected locally. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). To exploit this vulnerability, a attacker needs to convince a user to follow specific steps (social-engineering).
CVSS Score
6.1
EPSS Score
0.006
Published
2016-12-15
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Custom messages can be shown at the login screen to notify external users about issues with sharing links. This mechanism can be abused to inject arbitrary text messages. Users may get tricked to follow instructions injected by third parties as part of social engineering attacks.
CVSS Score
4.3
EPSS Score
0.002
Published
2016-12-15
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requested when parsing certain parts of the generated document. As a result an attacker can track access to a manipulated document. Usage of a document may get tracked and information about internal infrastructure may get exposed.
CVSS Score
4.3
EPSS Score
0.001
Published
2016-12-15
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending on the response type, content and latency, information about existence of hosts and services can be gathered. Attackers can get internal configuration information about the infrastructure of an operator to prepare subsequent attacks.
CVSS Score
5.8
EPSS Score
0.002
Published
2016-12-15


Contact Us

Shodan ® - All rights reserved