Open-Xchange Ox App Suite vulnerabilities
48 known vulnerabilities affecting open-xchange/ox_app_suite.
Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH2MEDIUM42
Vulnerabilities
Page 2 of 3
CVE-2022-43697MEDIUMCVSS 6.1fixed in 7.10.6v7.10.62023-04-15
CVE-2022-43697 [MEDIUM] CWE-79 CVE-2022-43697: OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
nvd
CVE-2022-43698MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-04-15
CVE-2022-43698 [MEDIUM] CWE-918 CVE-2022-43698: OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-lis
OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.
nvd
CVE-2022-43699MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-04-15
CVE-2022-43699 [MEDIUM] CWE-918 CVE-2022-43699: OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-li
OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address).
nvd
CVE-2022-29851CRITICALCVSS 9.8≤ 7.10.62022-10-25
CVE-2022-29851 [CRITICAL] CWE-78 CVE-2022-29851: documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, a
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
nvd
CVE-2022-31468MEDIUMCVSS 6.1≤ 8.22022-10-25
CVE-2022-31468 [MEDIUM] CWE-79 CVE-2022-31468: OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
nvd
CVE-2022-23100CRITICALCVSS 9.8≤ 7.10.62022-07-27
CVE-2022-23100 [CRITICAL] CWE-78 CVE-2022-23100: OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an emai
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
nvd
CVE-2022-24405CRITICALCVSS 9.8≤ 7.10.62022-07-27
CVE-2022-24405 [CRITICAL] CWE-78 CVE-2022-24405: OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentc
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
nvd
CVE-2022-24406MEDIUMCVSS 6.5≤ 7.10.62022-07-27
CVE-2022-24406 [MEDIUM] CWE-330 CVE-2022-24406: OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
nvd
CVE-2022-23101MEDIUMCVSS 6.1≤ 7.10.62022-07-27
CVE-2022-23101 [MEDIUM] CWE-79 CVE-2022-23101: OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
nvd
CVE-2021-44211MEDIUMCVSS 5.4≤ 7.10.52022-03-28
CVE-2021-44211 [MEDIUM] CWE-79 CVE-2021-44211: OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signa
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
nvd
CVE-2021-44212MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44212 [MEDIUM] CWE-79 CVE-2021-44212: OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substri
OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.
nvd
CVE-2021-44213MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44213 [MEDIUM] CWE-79 CVE-2021-44213: OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.
OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.
nvd
CVE-2021-44210MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44210 [MEDIUM] CWE-79 CVE-2021-44210: OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.
OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.
nvd
CVE-2021-44209MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44209 [MEDIUM] CWE-79 CVE-2021-44209: OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
nvd
CVE-2021-44208MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44208 [MEDIUM] CWE-79 CVE-2021-44208: OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
nvd
CVE-2021-33489MEDIUMCVSS 6.1≤ 7.10.52021-11-22
CVE-2021-33489 [MEDIUM] CWE-79 CVE-2021-33489: OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
nvd
CVE-2021-33490MEDIUMCVSS 6.1≤ 7.10.52021-11-22
CVE-2021-33490 [MEDIUM] CWE-79 CVE-2021-33490: OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
nvd
CVE-2021-38374MEDIUMCVSS 5.4≤ 7.10.52021-11-22
CVE-2021-38374 [MEDIUM] CWE-79 CVE-2021-38374: OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader referenc
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
nvd
CVE-2021-33491MEDIUMCVSS 6.5≤ 7.10.52021-11-22
CVE-2021-33491 [MEDIUM] CWE-22 CVE-2021-33491: OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, becau
OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
nvd
CVE-2021-38376MEDIUMCVSS 5.3≤ 7.10.52021-11-22
CVE-2021-38376 [MEDIUM] CWE-287 CVE-2021-38376: OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via th
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
nvd