CVE-2013-6997
Estado: ModificadaMedia (4.3)—
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents containing "crafted hyperlinks with script URL handlers."
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.32%
- Percentil entre todas las CVEs puntuadas: 70
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://software.open-xchange.com/OX6/doc/Release_Notes_for_Public_Patch_Release_1766_7.4.0_Rev21_2013_12_13.pdf
- http://www.osvdb.org/101714
- http://www.osvdb.org/101715
- http://www.securityfocus.com/archive/1/530681/100/0/threaded
- http://www.securityfocus.com/bid/64676
- http://www.securitytracker.com/id/1029554
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90113
- http://software.open-xchange.com/OX6/doc/Release_Notes_for_Public_Patch_Release_1766_7.4.0_Rev21_2013_12_13.pdf
- http://www.osvdb.org/101714
- http://www.osvdb.org/101715
- http://www.securityfocus.com/archive/1/530681/100/0/threaded
- http://www.securityfocus.com/bid/64676
- http://www.securitytracker.com/id/1029554
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90113
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-6997",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-01-09T00:55:03.097",
"references": [
{
"url": "http://software.open-xchange.com/OX6/doc/Release_Notes_for_Public_Patch_Release_1766_7.4.0_Rev21_2013_12_13.pdf",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/101714",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/101715",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/530681/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/64676",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id/1029554",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90113",
"source": "cve@mitre.org"
},
{
"url": "http://software.open-xchange.com/OX6/doc/Release_Notes_for_Public_Patch_Release_1766_7.4.0_Rev21_2013_12_13.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/101714",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/101715",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/530681/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/64676",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1029554",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90113",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents containing \"crafted hyperlinks with script URL handlers.\""
},
{
"lang": "es",
"value": "Multiple cross-site scripting (XSS) en Open-Xchange (OX) AppSuite 7.4.0 y anteriores que permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) un correo electrónico HTML con código CSS manipulado que contiene caracteres comodín o (2) la oficina documentos que contienen \"hipervínculos manipulados con manejadores de script de URL.\""
}
],
"lastModified": "2026-06-17T00:01:15.157",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2E10052-CF1B-4A96-87DD-8AEEBC96E4E6",
"versionEndIncluding": "7.4.0"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:6.20.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "983E5F3A-E7AD-4CCA-80D4-9C012AFCCDD4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:6.22.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F85EE0C-B7A0-455A-96F6-E4E6BA5D7216"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:6.22.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D9572CB-9A46-492E-BDCC-E01849EF0EC0"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "138461CD-9C27-40E5-B7A0-A37737B6E942"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "108BCEFD-3098-4919-9B0C-E80F6FA1C102"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDBB02DF-1022-4FE5-B5E1-198DC58F8C1B"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BF31219-8390-4676-A9C4-D625A016C71E"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75B04598-67CD-420B-92C9-9A7459295E11"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}