Open-xchange
Open-xchange Appsuite Frontend: vulnerabilidades y CVE
Open-xchange Appsuite Frontend tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-4367 | Alta (8.8) | 71% | — | 14 may 2024 | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. |
| CVE-2023-26450 | Media (5.4) | 0.73% | — | 2 ago 2023 | The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering… |
| CVE-2023-26449 | Media (5.4) | 0.73% | — | 2 ago 2023 | The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering… |
| CVE-2023-26448 | Media (5.4) | 0.66% | — | 2 ago 2023 | Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session… |
| CVE-2023-26447 | Media (5.4) | 0.66% | — | 2 ago 2023 | The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed… |
| CVE-2023-26446 | Media (5.4) | 0.66% | — | 2 ago 2023 | The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering… |
| CVE-2023-26445 | Media (5.4) | 0.66% | — | 2 ago 2023 | Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead… |
| CVE-2016-6846 | Media (6.1) | 1.2% | — | 29 mar 2017 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and… |