CVE-2023-29047
Estado: ModificadaAlta (7.3)—
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content which is accessible to the imageconverter SQL user account. None No publicly available exploits are known.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 7.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
- CWE-89
Referencias
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-29047",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-29047",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-12T14:32:45.858438Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@open-xchange.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 0.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "security@open-xchange.com",
"affectedData": [
{
"vendor": "OX Software GmbH",
"modules": [
"office"
],
"product": "OX App Suite",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "7.10.6-rev5"
},
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "8.12"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-11-02T14:15:11.280",
"references": [
{
"url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json",
"source": "security@open-xchange.com"
},
{
"url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "security@open-xchange.com"
},
{
"url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@open-xchange.com",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content which is accessible to the imageconverter SQL user account. None No publicly available exploits are known.\n\n"
},
{
"lang": "es",
"value": "Los endpoints de la API Imageconverter proporcionaban métodos que no validaban ni sanitizaban correctamente la entrada del cliente, lo que permitía inyectar declaraciones SQL arbitrarias. Un atacante con acceso a la red adyacente y potencialmente credenciales API podría leer y modificar el contenido de la base de datos al que puede acceder la cuenta de usuario SQL de imageconverter. Ninguno No se conocen exploits disponibles públicamente."
}
],
"lastModified": "2026-06-17T05:49:14.800",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59D4F30E-2F52-4948-9C69-C57472833C79",
"versionEndExcluding": "7.10.6"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A144D75D-60A8-4EE0-813C-F658C626B2AA"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6069:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DA66230-DE02-4881-A893-E9E78286B157"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6073:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "955F3DFB-6479-4867-B62A-82730DBEB498"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6080:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "327D1B56-0D05-4D99-91D4-CC1F0AC32972"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6085:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0CD0684-C431-47F8-A2F4-1936D5C5A72B"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6093:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAA6A4A7-C1EE-4716-9F4D-2FF4C4D5FEC8"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6102:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0968764-CCEE-47A7-9111-E106D887DA43"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6112:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16589FBB-F0CD-4041-8141-5C89FCCA72AF"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6121:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CB877EE-A5FE-4FF7-9D21-5C1CFA7343D4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6133:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DF5FB90-8D6D-4F99-B454-411B1DFFA630"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6138:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F58876B9-6C2E-4048-A793-B441A84E86F5"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6141:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5F177CB-CC45-45A0-9D02-C14A13ECC7A3"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6146:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A89A4192-54E9-4899-8C7B-6C7F7E650D5C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6147:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2DC1357-9CD5-415F-A190-2F3F4498EF96"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6148:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D78ACF64-2802-44DD-AF7A-1BD5EA7F9908"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6150:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8F675FA-1684-413A-B1BE-1C5434AC2862"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6156:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3F1FDC3-35B2-4BDB-A685-75BC72588179"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6161:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B1E509D-2F41-4296-86D2-6BD71783060F"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6166:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC93EA37-F341-45EC-B651-4F326FB8C613"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6173:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A4DB8A6-1702-462C-BFCB-39F91D2EFCE1"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6176:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC0AEFDB-D033-47FC-93FC-8652F922BB8C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6178:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5354768-6527-43C2-B492-A8C14AB4E784"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6189:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D83F26D1-B8C6-4114-81EC-810DD5412DC8"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6194:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9EBC010-9963-4636-96F7-A121FCF755A7"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6199:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F626D64B-C301-4CD8-94B4-48689BD3F29C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6204:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E32810C-7B35-42F1-BCA5-E10C02BE2215"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6205:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6539D059-8614-4C26-93C4-C2DDCC5D35E2"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6209:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E359EE75-A2F9-479B-B757-CAE1064AB8F4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6210:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BCABDEF-D292-406E-B53C-AFF22484E916"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6214:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABE8872C-B1DD-4A45-8EF8-E8C355CA6C54"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6215:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44B20B83-833A-4C68-8693-365BD046C157"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6216:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E254E6D1-D18E-4A2A-A2FF-7D03F39E65DD"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6218:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F0C5E53-4D15-425A-B4CF-5869353724BF"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6219:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F4BF5F1-F316-4BAC-83E0-DEAC8C50754E"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6220:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CDD03A8-5B86-4B87-9C29-6C967261C5C0"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6227:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6071E15F-4D59-41DC-A4D4-7D1AA392A1F2"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6230:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C72C1CEB-7BF7-4A5F-B2E9-397F86CCBF4E"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6233:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B0F0218-4224-4084-B38D-9719D3782C03"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6235:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFC41329-1AD6-4575-A22D-977EC5539DA4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6236:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "217A06B7-0823-4508-BC0C-AD792BA88F7B"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6239:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "246E98B2-A6C8-4410-AA6A-7E81EE8C5E76"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6241:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74D1EC02-D009-45DA-B1EC-2219E0F0183C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@open-xchange.com"
}