CVE-2024-25582Cross-site Scripting in Gmbh OX APP Suite

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 60.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 19

Description

Module savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers could perform malicious API requests or extract information from the users account. Exploiting this vulnerability requires temporary access to an account or successful social engineering to make a user follow a prepared link to a malicious account. Please deploy the provided updates and patch releases. The savepoint module path has been restricted to modules that provide the feat

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

CVEListV5open-xchange_gmbh/ox_app_suite7.10.6-rev42

🔴Vulnerability Details

2
GHSA
GHSA-59hv-jp72-r98g: Module savepoints could be abused to inject references to malicious code delivered through the same domain2024-08-19
CVEList
CVE-2024-25582: Module savepoints could be abused to inject references to malicious code delivered through the same domain2024-08-19
CVE-2024-25582 — Cross-site Scripting | cvebase