VendorsOpen-Xchangeopen-xchange_appsuiteany version
Vulnerabilities

Open-Xchange AppSuite any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

125CVEs
CVE-2018-5754
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.
Published 2018-06-15 · Modified
5.41 PoCEPSS 0.030
CVE-2018-13104
OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)
Published 2019-03-17 · Modified
5.4EPSS 0.008
CVE-2016-3173
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The aria-label parameter of tiles at the Portal can be used to inject script code. Those labels use the name of the file (e.g. an image) which gets displayed at the portal application. Using script code at the file name leads to script execution. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). Users actively need to add a file to the portal to enable this attack. In case of shared files however, a internal attacker may modify a previously embedded file to carry a malicious file name. Furthermore this vulnerability can be used to persistently execute code that got injected by a temporary script execution vulnerability.
Published 2016-12-15 · Modified
5.4EPSS 0.007
CVE-2019-11522
OX App Suite 7.10.0 to 7.10.2 allows XSS.
Published 2019-08-20 · Modified
5.4EPSS 0.007
CVE-2020-12646
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
Published 2020-08-31 · Modified
5.4EPSS 0.005
CVE-2017-13668
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-23 · Modified
5.4EPSS 0.005
CVE-2017-17061
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Published 2019-05-23 · Modified
5.4EPSS 0.005
CVE-2023-41708
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.
Published 2024-02-12 · Modified
5.4EPSS 0.005
CVE-2023-29044
Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating parties does now get escaped to avoid code execution. No publicly available exploits are known.
Published 2023-11-02 · Modified
5.4EPSS 0.004
CVE-2023-29045
Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating parties does now gets checked for validity to avoid code execution. No publicly available exploits are known.
Published 2023-11-02 · Modified
5.4EPSS 0.004
CVE-2022-29852
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
Published 2022-12-26 · Modified
5.4EPSS 0.004
CVE-2022-29853
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
Published 2022-12-26 · Modified
5.4EPSS 0.004
CVE-2018-12610
OX App Suite 7.8.4 and earlier allows Information Exposure.
Published 2019-01-29 · Modified
5.3EPSS 0.012
CVE-2017-8341
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
Published 2019-05-22 · Modified
5.3EPSS 0.010
CVE-2022-37311
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
Published 2022-12-26 · Modified
5.3EPSS 0.009
CVE-2022-37312
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.
Published 2022-12-26 · Modified
5.3EPSS 0.009
CVE-2017-9809
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.
Published 2019-05-22 · Modified
5.3EPSS 0.009
CVE-2022-37313
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
Published 2022-12-26 · Modified
5.3EPSS 0.007
CVE-2020-15002
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
Published 2020-10-23 · Modified
5.0EPSS 0.016
CVE-2019-18846
OX App Suite through 7.10.2 allows SSRF.
Published 2020-02-21 · Modified
5.0EPSS 0.009
CVE-2020-12644
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
Published 2020-08-31 · Modified
5.0EPSS 0.007
CVE-2018-5756
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via the task id in a delete action to api/tasks.
Published 2018-06-15 · Modified
4.31 PoCEPSS 0.056
CVE-2015-5375
Cross-site scripting (XSS) vulnerability in unspecified dialogs for printing content in the Front End in Open-Xchange Server 6 and OX App Suite before 6.22.8-rev8, 6.22.9 before 6.22.9-rev15m, 7.x before 7.6.1-rev25, and 7.6.2 before 7.6.2-rev20 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to object properties.
Published 2015-09-28 · Modified
4.3EPSS 0.020
CVE-2014-8993
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev40, 7.6.0 before 7.6.0-rev32, and 7.6.1 before 7.6.1-rev11 allows remote attackers to inject arbitrary web script or HTML via a crafted XHTML file with the application/xhtml+xml MIME type.
Published 2015-01-07 · Modified
4.3EPSS 0.019
CVE-2014-5234
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via a folder publication name.
Published 2014-09-17 · Modified
4.3EPSS 0.019
CVE-2014-5235
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via vectors related to unspecified fields in RSS feeds.
Published 2014-09-17 · Modified
4.3EPSS 0.019
CVE-2013-7141
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to crafted "<%" tags.
Published 2014-01-26 · Modified
4.3EPSS 0.018
CVE-2013-7142
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified oAuth API functions.
Published 2014-01-26 · Modified
4.3EPSS 0.018
CVE-2013-6997
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents containing "crafted hyperlinks with script URL handlers."
Published 2014-01-09 · Modified
4.3EPSS 0.013
CVE-2014-1679
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite before 7.2.2-rev31, 7.4.0 before 7.4.0-rev27, and 7.4.1 before 7.4.1-rev17 allows remote attackers to inject arbitrary web script or HTML via the header in an attached SVG file.
Published 2015-01-05 · Modified
4.3EPSS 0.012
CVE-2013-7143
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 allows remote attackers to inject arbitrary web script or HTML via the title in a mail filter rule.
Published 2014-01-26 · Modified
4.3EPSS 0.012
CVE-2016-4048
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Custom messages can be shown at the login screen to notify external users about issues with sharing links. This mechanism can be abused to inject arbitrary text messages. Users may get tricked to follow instructions injected by third parties as part of social engineering attacks.
Published 2016-12-15 · Modified
4.3EPSS 0.012
CVE-2014-2391
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potentially useful password-pattern information by reading (1) a web-server access log, (2) a web-server Referer log, or (3) browser history that contains this string because of its presence in a GET request.
Published 2014-04-17 · Modified
4.3EPSS 0.011
CVE-2014-2392
The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 places a password in a GET request, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
Published 2014-04-17 · Modified
4.3EPSS 0.011
CVE-2016-6852
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file exists or not. Attackers may discover specific system files or library versions on the middleware server to prepare further attacks.
Published 2016-12-15 · Modified
4.3EPSS 0.010
CVE-2013-6009
CRLF injection vulnerability in Open-Xchange AppSuite before 7.2.2, when using AJP in certain conditions, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the ajax/defer servlet.
Published 2013-10-03 · Modified
4.3EPSS 0.010
CVE-2014-2393
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.
Published 2014-04-17 · Modified
4.3EPSS 0.010
CVE-2016-4047
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requested when parsing certain parts of the generated document. As a result an attacker can track access to a manipulated document. Usage of a document may get tracked and information about internal infrastructure may get exposed.
Published 2016-12-15 · Modified
4.3EPSS 0.008
CVE-2017-15029
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
Published 2019-05-23 · Modified
4.3EPSS 0.007
CVE-2020-12643
OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.
Published 2020-08-31 · Modified
4.3EPSS 0.006
← Prev3 / 4Next →