VendorsOpen-Xchangeopen-xchange_appsuiteany version
Vulnerabilities

Open-Xchange AppSuite any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

125CVEs
CVE-2019-16717
OX App Suite through 7.10.2 has XSS.
Published 2020-01-06 · Modified
6.1EPSS 0.015
CVE-2016-5124
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev14. Adding images from external sources to HTML editors by drag&drop can potentially lead to script code execution in the context of the active user. To exploit this, a user needs to be tricked to use an image from a specially crafted website and add it to HTML editor areas of OX App Suite, for example E-Mail Compose or OX Text. This specific attack circumvents typical XSS filters and detection mechanisms since the code is not loaded from an external service but injected locally. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). To exploit this vulnerability, a attacker needs to convince a user to follow specific steps (social-engineering).
Published 2016-12-15 · Modified
6.1EPSS 0.013
CVE-2018-12611
OX App Suite 7.8.4 and earlier allows Directory Traversal.
Published 2019-01-29 · Modified
6.1EPSS 0.012
CVE-2021-23928
OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.
Published 2021-01-12 · Modified
6.1EPSS 0.011
CVE-2021-23934
OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.
Published 2021-01-12 · Modified
6.1EPSS 0.011
CVE-2021-23930
OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.
Published 2021-01-12 · Modified
6.1EPSS 0.011
CVE-2021-23933
OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
Published 2021-01-12 · Modified
6.1EPSS 0.011
CVE-2021-23932
OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.
Published 2021-01-12 · Modified
6.1EPSS 0.011
CVE-2021-23931
OX App Suite through 7.10.4 allows XSS via an inline binary file.
Published 2021-01-12 · Modified
6.1EPSS 0.011
CVE-2021-23929
OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI.
Published 2021-01-12 · Modified
6.1EPSS 0.011
CVE-2020-28945
OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://onerror=Function.constructor, in a Notes item.
Published 2021-05-03 · Modified
6.1EPSS 0.011
CVE-2021-23935
OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.
Published 2021-01-12 · Modified
6.1EPSS 0.011
CVE-2017-6913
Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.
Published 2018-09-18 · Modified
6.1EPSS 0.010
CVE-2021-31935
OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandled in the scheduling view.
Published 2021-04-30 · Modified
6.1EPSS 0.009
CVE-2021-31934
OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.
Published 2021-04-30 · Modified
6.1EPSS 0.009
CVE-2021-23936
OX App Suite through 7.10.4 allows XSS via the subject of a task.
Published 2021-01-12 · Modified
6.1EPSS 0.009
CVE-2017-15030
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-23 · Modified
6.1EPSS 0.009
CVE-2017-5213
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-23 · Modified
6.1EPSS 0.009
CVE-2017-5864
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-22 · Modified
6.1EPSS 0.009
CVE-2017-12885
OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-10 · Modified
6.1EPSS 0.009
CVE-2016-6843
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code can be injected to contact names. When adding those contacts to a group, the script code gets executed in the context of the user which creates or changes the group by using autocomplete. In most cases this is a user with elevated permissions. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2016-6844
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within SVG files is maintained when opening such files "in browser" based on our Mail or Drive app. In case of "a" tags, this may include link targets with base64 encoded "data" references. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2016-6845
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within hyperlinks at HTML E-Mails is not getting correctly sanitized when using base64 encoded "data" resources. This allows an attacker to provide hyperlinks that may execute script code instead of directing to a proper location. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2016-6847
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when calling the related cover URL. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2016-6850
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as profile pictures. In case their XML structure contains iframes and script code, that code may get executed when calling the related picture URL or viewing the related person's image within a browser. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2016-4026
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The content sanitizer component has an issue with filtering malicious content in case invalid HTML code is provided. In such cases the filter will output a unsanitized representation of the content. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). Attackers can use this issue for filter evasion to inject script code later on.
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2016-4045
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of the user. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). The attacker needs to reside within the same context to make this attack work.
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2016-6842
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user's name to JS code makes that code execute when selecting that user's "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2017-9808
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-22 · Modified
6.1EPSS 0.007
CVE-2022-37307
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2022-37308
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2022-31469
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2022-37310
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2022-37309
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2023-41703
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.
Published 2024-02-12 · Modified
6.1EPSS 0.005
CVE-2023-29043
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when performing certain actions, like copying content. The relevant attribute does now get encoded to avoid the possibility of executing script code. No publicly available exploits are known.
Published 2023-11-02 · Modified
6.1EPSS 0.003
CVE-2016-4046
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending on the response type, content and latency, information about existence of hosts and services can be gathered. Attackers can get internal configuration information about the infrastructure of an operator to prepare subsequent attacks.
Published 2016-12-15 · Modified
5.8EPSS 0.012
CVE-2020-24700
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
Published 2021-01-12 · Modified
5.5EPSS 0.012
CVE-2018-13103
OX App Suite 7.8.4 and earlier allows SSRF.
Published 2019-03-17 · Modified
5.5EPSS 0.008
CVE-2016-6848
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a trusted domain without authentication that, if executed by the user, may lead to local code execution.
Published 2016-12-15 · Modified
5.5EPSS 0.004
← Prev2 / 4Next →