Open-Xchange Ox App Suite vulnerabilities

48 known vulnerabilities affecting open-xchange/ox_app_suite.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH2MEDIUM42

Vulnerabilities

Page 2 of 3
CVE-2022-43697MEDIUMCVSS 6.1fixed in 7.10.6v7.10.62023-04-15
CVE-2022-43697 [MEDIUM] CWE-79 CVE-2022-43697: OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob. OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
nvd
CVE-2022-43698MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-04-15
CVE-2022-43698 [MEDIUM] CWE-918 CVE-2022-43698: OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-lis OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.
nvd
CVE-2022-43699MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-04-15
CVE-2022-43699 [MEDIUM] CWE-918 CVE-2022-43699: OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-li OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address).
nvd
CVE-2022-29851CRITICALCVSS 9.8≤ 7.10.62022-10-25
CVE-2022-29851 [CRITICAL] CWE-78 CVE-2022-29851: documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, a documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
nvd
CVE-2022-31468MEDIUMCVSS 6.1≤ 8.22022-10-25
CVE-2022-31468 [MEDIUM] CWE-79 CVE-2022-31468: OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
nvd
CVE-2022-23100CRITICALCVSS 9.8≤ 7.10.62022-07-27
CVE-2022-23100 [CRITICAL] CWE-78 CVE-2022-23100: OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an emai OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
nvd
CVE-2022-24405CRITICALCVSS 9.8≤ 7.10.62022-07-27
CVE-2022-24405 [CRITICAL] CWE-78 CVE-2022-24405: OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentc OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
nvd
CVE-2022-24406MEDIUMCVSS 6.5≤ 7.10.62022-07-27
CVE-2022-24406 [MEDIUM] CWE-330 CVE-2022-24406: OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
nvd
CVE-2022-23101MEDIUMCVSS 6.1≤ 7.10.62022-07-27
CVE-2022-23101 [MEDIUM] CWE-79 CVE-2022-23101: OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message. OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
nvd
CVE-2021-44211MEDIUMCVSS 5.4≤ 7.10.52022-03-28
CVE-2021-44211 [MEDIUM] CWE-79 CVE-2021-44211: OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signa OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
nvd
CVE-2021-44212MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44212 [MEDIUM] CWE-79 CVE-2021-44212: OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substri OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.
nvd
CVE-2021-44213MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44213 [MEDIUM] CWE-79 CVE-2021-44213: OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message. OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.
nvd
CVE-2021-44210MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44210 [MEDIUM] CWE-79 CVE-2021-44210: OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data. OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.
nvd
CVE-2021-44209MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44209 [MEDIUM] CWE-79 CVE-2021-44209: OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO. OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
nvd
CVE-2021-44208MEDIUMCVSS 6.1≤ 7.10.52022-03-28
CVE-2021-44208 [MEDIUM] CWE-79 CVE-2021-44208: OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat. OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
nvd
CVE-2021-33489MEDIUMCVSS 6.1≤ 7.10.52021-11-22
CVE-2021-33489 [MEDIUM] CWE-79 CVE-2021-33489: OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file. OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
nvd
CVE-2021-33490MEDIUMCVSS 6.1≤ 7.10.52021-11-22
CVE-2021-33490 [MEDIUM] CWE-79 CVE-2021-33490: OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature. OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
nvd
CVE-2021-38374MEDIUMCVSS 5.4≤ 7.10.52021-11-22
CVE-2021-38374 [MEDIUM] CWE-79 CVE-2021-38374: OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader referenc OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
nvd
CVE-2021-33491MEDIUMCVSS 6.5≤ 7.10.52021-11-22
CVE-2021-33491 [MEDIUM] CWE-22 CVE-2021-33491: OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, becau OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
nvd
CVE-2021-38376MEDIUMCVSS 5.3≤ 7.10.52021-11-22
CVE-2021-38376 [MEDIUM] CWE-287 CVE-2021-38376: OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via th OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
nvd