cbcvebase.
CVE-2024-23193
published 2024-05-06

CVE-2024-23193: E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node…

PriorityP428medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
0.55%
41.5th percentile
E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared. Successful exploitation requires good timing and modification of multiple request parameters. Please deploy the provided updates and patch releases. The cache for PDF exports now takes user session information into consideration when performing authorization decisions. No publicly available exploits are known.

Affected

2 ranges
VendorProductVersion rangeFixed in
open-xchangeox_app_suite< 8.228.22
open-xchange_gmbhox_app_suite<= 8.21
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.