VendorsOpen-Xchangeopen-xchange_appsuiteall versions
Vulnerabilities

Open-Xchange AppSuite

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

157CVEs
CVE-2016-6842
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user's name to JS code makes that code execute when selecting that user's "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Published 2016-12-15 · Modified
6.1EPSS 0.007
CVE-2017-9808
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-22 · Modified
6.1EPSS 0.007
CVE-2022-37307
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2022-31469
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2022-37308
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2022-37309
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2022-37310
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
Published 2022-12-26 · Modified
6.1EPSS 0.005
CVE-2023-41703
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.
Published 2024-02-12 · Modified
6.1EPSS 0.005
CVE-2023-29043
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when performing certain actions, like copying content. The relevant attribute does now get encoded to avoid the possibility of executing script code. No publicly available exploits are known.
Published 2023-11-02 · Modified
6.1EPSS 0.003
CVE-2021-26699
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
Published 2021-07-22 · Modified
5.8EPSS 0.020
CVE-2016-4046
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending on the response type, content and latency, information about existence of hosts and services can be gathered. Attackers can get internal configuration information about the infrastructure of an operator to prepare subsequent attacks.
Published 2016-12-15 · Modified
5.8EPSS 0.012
CVE-2020-24700
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
Published 2021-01-12 · Modified
5.5EPSS 0.012
CVE-2018-13103
OX App Suite 7.8.4 and earlier allows SSRF.
Published 2019-03-17 · Modified
5.5EPSS 0.008
CVE-2019-14225
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
Published 2019-10-14 · Modified
5.5EPSS 0.007
CVE-2016-6848
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a trusted domain without authentication that, if executed by the user, may lead to local code execution.
Published 2016-12-15 · Modified
5.5EPSS 0.004
CVE-2018-5754
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.
Published 2018-06-15 · Modified
5.41 PoCEPSS 0.030
CVE-2020-8542
OX App Suite through 7.10.3 allows XSS.
Published 2020-06-16 · Modified
5.4EPSS 0.012
CVE-2018-13104
OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)
Published 2019-03-17 · Modified
5.4EPSS 0.008
CVE-2016-3173
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The aria-label parameter of tiles at the Portal can be used to inject script code. Those labels use the name of the file (e.g. an image) which gets displayed at the portal application. Using script code at the file name leads to script execution. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). Users actively need to add a file to the portal to enable this attack. In case of shared files however, a internal attacker may modify a previously embedded file to carry a malicious file name. Furthermore this vulnerability can be used to persistently execute code that got injected by a temporary script execution vulnerability.
Published 2016-12-15 · Modified
5.4EPSS 0.007
CVE-2019-11522
OX App Suite 7.10.0 to 7.10.2 allows XSS.
Published 2019-08-20 · Modified
5.4EPSS 0.007
CVE-2020-12646
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
Published 2020-08-31 · Modified
5.4EPSS 0.005
CVE-2017-13668
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-23 · Modified
5.4EPSS 0.005
CVE-2017-17061
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-23 · Modified
5.4EPSS 0.005
CVE-2023-41708
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.
Published 2024-02-12 · Modified
5.4EPSS 0.005
CVE-2023-29044
Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating parties does now get escaped to avoid code execution. No publicly available exploits are known.
Published 2023-11-02 · Modified
5.4EPSS 0.004
CVE-2023-29045
Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating parties does now gets checked for validity to avoid code execution. No publicly available exploits are known.
Published 2023-11-02 · Modified
5.4EPSS 0.004
CVE-2022-29852
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
Published 2022-12-26 · Modified
5.4EPSS 0.004
CVE-2022-29853
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
Published 2022-12-26 · Modified
5.4EPSS 0.004
CVE-2014-2078
The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto configuration for external accounts.
Published 2018-04-10 · Modified
5.3EPSS 0.013
CVE-2018-12610
OX App Suite 7.8.4 and earlier allows Information Exposure.
Published 2019-01-29 · Modified
5.3EPSS 0.012
CVE-2017-8341
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
Published 2019-05-22 · Modified
5.3EPSS 0.010
CVE-2022-37311
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
Published 2022-12-26 · Modified
5.3EPSS 0.009
CVE-2022-37312
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.
Published 2022-12-26 · Modified
5.3EPSS 0.009
CVE-2017-9809
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.
Published 2019-05-22 · Modified
5.3EPSS 0.009
CVE-2022-37313
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
Published 2022-12-26 · Modified
5.3EPSS 0.007
CVE-2020-15002
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
Published 2020-10-23 · Modified
5.0EPSS 0.016
CVE-2013-2582
CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP headers and conduct open redirect attacks by leveraging improper sanitization of whitespace characters.
Published 2013-09-05 · Modified
5.0EPSS 0.010
CVE-2019-18846
OX App Suite through 7.10.2 allows SSRF.
Published 2020-02-21 · Modified
5.0EPSS 0.009
CVE-2020-12644
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
Published 2020-08-31 · Modified
5.0EPSS 0.007
CVE-2013-5035
Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.
Published 2013-09-05 · Modified
4.9EPSS 0.007
← Prev3 / 4Next →