Open-Xchange Appsuite Frontend vulnerabilities

8 known vulnerabilities affecting open-xchange/open-xchange_appsuite_frontend.

Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2024-4367HIGHCVSS 8.8PoCfixed in 7.10.6v7.10.62024-05-14
CVE-2024-4367 [HIGH] CWE-754 CVE-2024-4367: A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execu A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2023-26449MEDIUMCVSS 5.4≤ 7.10.62023-08-02
CVE-2023-26449 [MEDIUM] CWE-79 CVE-2023-26449: The "OX Chat" web service did not specify a media-type when processing responses by external resourc The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lu
nvd
CVE-2023-26445MEDIUMCVSS 5.4≤ 7.10.62023-08-02
CVE-2023-26445 [MEDIUM] CWE-79 CVE-2023-26445: Frontend themes are defined by user-controllable jslob settings and could point to a malicious resou Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporar
nvd
CVE-2023-26447MEDIUMCVSS 5.4≤ 7.10.62023-08-02
CVE-2023-26447 [MEDIUM] CWE-79 CVE-2023-26447: The "upsell" widget for the portal allows to specify a product description. This description taken f The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit t
nvd
CVE-2023-26450MEDIUMCVSS 5.4≤ 7.10.62023-08-02
CVE-2023-26450 [MEDIUM] CWE-79 CVE-2023-26450: The "OX Count" web service did not specify a media-type when processing responses by external resour The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or l
nvd
CVE-2023-26448MEDIUMCVSS 5.4≤ 7.10.62023-08-02
CVE-2023-26448 [MEDIUM] CWE-79 CVE-2023-26448: Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malici Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the
nvd
CVE-2023-26446MEDIUMCVSS 5.4≤ 7.10.6≥ 8.10, < 8.122023-08-02
CVE-2023-26446 [MEDIUM] CWE-79 CVE-2023-26446: The users clientID at "application passwords" was not sanitized or escaped before being added to DOM The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure
nvd
CVE-2016-6846MEDIUMCVSS 6.1v7.6.2v7.8.0+1 more2017-03-29
CVE-2016-6846 [MEDIUM] CWE-79 CVE-2016-6846: Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7 Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before 7.8.2-rev5; and Documentconverter-API
nvd