CVE-2013-5698Cross-site Scripting in Appsuite

Severity
3.5LOWNVD
CNA4.3
EPSS
0.2%
top 63.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 5
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML via a delivery=view action, aka Bug ID 26373, a different vulnerability than CVE-2013-3106.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-f775-4rjm-m64p: Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 62022-05-17
CVEList
CVE-2013-5698: Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 62013-09-05
CVE-2013-5698 — Cross-site Scripting in Appsuite | cvebase