Open-Xchange Appsuite vulnerabilities

146 known vulnerabilities affecting open-xchange/open-xchange_appsuite.

Total CVEs
146
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM117LOW5

Vulnerabilities

Page 3 of 8
CVE-2021-23927MEDIUMCVSS 6.4≤ 7.10.42021-01-12
CVE-2021-23927 [MEDIUM] CWE-918 CVE-2021-23927: OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
nvd
CVE-2020-24701MEDIUMCVSS 6.1PoC≤ 7.10.42021-01-12
CVE-2020-24701 [MEDIUM] CWE-79 CVE-2020-24701: OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
nvd
CVE-2021-23933MEDIUMCVSS 6.1≤ 7.10.32021-01-12
CVE-2021-23933 [MEDIUM] CWE-79 CVE-2021-23933: OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL. OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
nvd
CVE-2020-24700MEDIUMCVSS 5.4≤ 7.10.32021-01-12
CVE-2020-24700 [MEDIUM] CWE-918 CVE-2020-24700: OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
nvd
CVE-2020-15004MEDIUMCVSS 4.8v7.10.2v7.10.32020-10-23
CVE-2020-15004 [MEDIUM] CWE-79 CVE-2020-15004: OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS. OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
nvd
CVE-2020-15002MEDIUMCVSS 5.0≤ 7.10.32020-10-23
CVE-2020-15002 [MEDIUM] CWE-918 CVE-2020-15002: OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
nvd
CVE-2020-15003MEDIUMCVSS 4.3v7.10.2v7.10.32020-10-23
CVE-2020-15003 [MEDIUM] CVE-2020-15003: OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).
nvd
CVE-2020-12645CRITICALCVSS 9.8≥ 7.10.1, ≤ 7.10.32020-08-31
CVE-2020-12645 [CRITICAL] CWE-307 CVE-2020-12645: OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agen OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
nvd
CVE-2020-12643MEDIUMCVSS 4.3≤ 7.10.32020-08-31
CVE-2020-12643 [MEDIUM] CWE-639 CVE-2020-12643: OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.
nvd
CVE-2020-12644MEDIUMCVSS 5.0≤ 7.10.32020-08-31
CVE-2020-12644 [MEDIUM] CWE-918 CVE-2020-12644: OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list AP OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
nvd
CVE-2020-12646MEDIUMCVSS 5.4≤ 7.10.32020-08-31
CVE-2020-12646 [MEDIUM] CWE-79 CVE-2020-12646: OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
nvd
CVE-2020-8543HIGHCVSS 7.5v7.8.4v7.10.1+2 more2020-06-16
CVE-2020-8543 [HIGH] CWE-20 CVE-2020-8543: OX App Suite through 7.10.3 has Improper Input Validation. OX App Suite through 7.10.3 has Improper Input Validation.
nvd
CVE-2014-5236HIGHCVSS 7.5≤ 7.4.1v7.4.2+1 more2020-01-31
CVE-2014-5236 [HIGH] CWE-22 CVE-2014-5236: Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
nvd
CVE-2014-5238HIGHCVSS 7.8≤ 7.4.1v7.4.2+1 more2020-01-14
CVE-2014-5238 [HIGH] CWE-611 CVE-2014-5238: XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x b XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.
nvd
CVE-2019-16716MEDIUMCVSS 6.6≤ 7.10.22020-01-06
CVE-2019-16716 [MEDIUM] CWE-276 CVE-2019-16716: OX App Suite through 7.10.2 has Incorrect Access Control. OX App Suite through 7.10.2 has Incorrect Access Control.
nvd
CVE-2013-7485MEDIUMCVSS 6.1v7.2.2v7.4.02020-01-02
CVE-2013-7485 [MEDIUM] CVE-2013-7485: Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7 Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects differen
nvd
CVE-2013-6242MEDIUMCVSS 6.1v6.22.3v6.22.4+2 more2020-01-02
CVE-2013-6242 [MEDIUM] CWE-79 CVE-2013-6242: Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the body of the email and the publication name were SPLIT from this CVE ID becaus
nvd
CVE-2013-7486MEDIUMCVSS 6.1v7.2.2v7.4.02020-01-02
CVE-2013-7486 [MEDIUM] CVE-2013-7486: Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7 Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions.
nvd
CVE-2019-14226HIGHCVSS 8.1≤ 7.10.22019-10-14
CVE-2019-14226 [HIGH] CWE-281 CVE-2019-14226: OX App Suite through 7.10.2 has Insecure Permissions. OX App Suite through 7.10.2 has Insecure Permissions.
nvd
CVE-2019-11806LOWCVSS 3.3≥ 7.6.3, ≤ 7.10.12019-08-20
CVE-2019-11806 [LOW] CWE-732 CVE-2019-11806: OX App Suite 7.10.1 and earlier has Insecure Permissions. OX App Suite 7.10.1 and earlier has Insecure Permissions.
nvd
Open-Xchange Appsuite vulnerabilities | cvebase