Open-Xchange Ox App Suite vulnerabilities

48 known vulnerabilities affecting open-xchange/ox_app_suite.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH2MEDIUM42

Vulnerabilities

Page 3 of 3
CVE-2021-33488MEDIUMCVSS 6.1≤ 7.10.52021-11-22
CVE-2021-33488 [MEDIUM] CWE-20 CVE-2021-33488: chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Ch chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.
nvd
CVE-2021-33492MEDIUMCVSS 6.1v7.10.52021-11-22
CVE-2021-33492 [MEDIUM] CWE-79 CVE-2021-33492: OX App Suite 7.10.5 allows XSS via an OX Chat room name. OX App Suite 7.10.5 allows XSS via an OX Chat room name.
nvd
CVE-2021-33493MEDIUMCVSS 6.0≤ 7.10.52021-11-22
CVE-2021-33493 [MEDIUM] CWE-94 CVE-2021-33493: The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
nvd
CVE-2021-33495MEDIUMCVSS 6.1v7.10.52021-11-22
CVE-2021-33495 [MEDIUM] CWE-79 CVE-2021-33495: OX App Suite 7.10.5 allows XSS via an OX Chat system message. OX App Suite 7.10.5 allows XSS via an OX Chat system message.
nvd
CVE-2021-38378MEDIUMCVSS 4.3≤ 7.10.52021-11-22
CVE-2021-38378 [MEDIUM] CVE-2021-38378: OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
nvd
CVE-2021-33494MEDIUMCVSS 6.1v7.10.52021-11-22
CVE-2021-33494 [MEDIUM] CWE-79 CVE-2021-33494: OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering. OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
nvd
CVE-2021-38375MEDIUMCVSS 6.1≤ 7.10.52021-11-22
CVE-2021-38375 [MEDIUM] CWE-79 CVE-2021-38375: OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
nvd
CVE-2021-38377MEDIUMCVSS 6.1≤ 7.10.52021-11-22
CVE-2021-38377 [MEDIUM] CWE-330 CVE-2021-38377: OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncate OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
nvd
Open-Xchange Ox App Suite vulnerabilities | cvebase