CVE-2016-4026Cross-site Scripting in Appsuite

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 56.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 15
Latest updateMay 14

Description

An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The content sanitizer component has an issue with filtering malicious content in case invalid HTML code is provided. In such cases the filter will output a unsanitized representation of the content. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). Attackers can use this issue for filter e

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-wxjw-vgmv-8955: An issue was discovered in Open-Xchange OX App Suite before 72022-05-14
CVEList
CVE-2016-4026: An issue was discovered in Open-Xchange OX App Suite before 72016-12-15
CVE-2016-4026 — Cross-site Scripting in Appsuite | cvebase