« Volver al listado

CVE-2023-29052

Estado: ModificadaMedia (5.4)—

Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-29052",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-29052",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-01-08T14:06:01.468275Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@open-xchange.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security@open-xchange.com",
      "affectedData": [
        {
          "vendor": "Open-Xchange GmbH",
          "modules": [
            "frontend"
          ],
          "product": "OX App Suite",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "7.10.6-rev34"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-01-08T09:15:20.680",
  "references": [
    {
      "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0006.json",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@open-xchange.com"
    },
    {
      "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf",
      "tags": [
        "Release Notes"
      ],
      "source": "security@open-xchange.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Jan/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0006.json",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@open-xchange.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known."
    },
    {
      "lang": "es",
      "value": "Los usuarios pudieron definir textos de exención de responsabilidad para un cuadro de diálogo de tienda de ventas adicionales que contendría código de script que no se sanitizó correctamente. Los atacantes podrían atraer a las víctimas a cuentas de usuario con código de script malicioso y obligarlas a ejecutarlo en el contexto de un dominio confiable. Agregamos sanitización para este contenido. No se conocen exploits disponibles públicamente."
    }
  ],
  "lastModified": "2026-06-17T05:49:15.627",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A4EAD2E-C3C3-4C79-8C42-375FFE638486"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev01:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39198733-D227-4935-9A60-1026040D262F"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev02:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C86EE81-8CD4-4131-969A-BDA24B9B48E8"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev03:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9E9C869-7DA9-4EFA-B613-82BA127F6CE5"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev04:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8FAA329-5893-412B-8349-4DA3023CC76E"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev05:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB6A57A4-B18D-498D-9A8C-406797A6255C"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev06:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F0977F0-90B4-48B4-BED6-C218B5CA5E03"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev07:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D55DE67-8F93-48F3-BE54-D3A065479281"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev08:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D27980B4-B71B-4DA8-B130-F0B5929F8E65"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev09:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD1709BC-7DEB-4508-B3C3-B20F5FD001A3"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08A6BDD5-259E-4DC3-A548-00CD0D459749"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8166FF4-77D8-4A12-92E5-615B3DA2E602"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "999F057B-7918-461A-B60C-3BE72E92CDC9"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88FD1550-3715-493E-B674-9ECF3DD7A813"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F31A4949-397F-4D1B-8AEA-AC7B335722F8"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev15:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D33A91D4-CE21-486D-9469-B09060B8C637"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev16:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E3E5CD2-7631-4DBE-AB4D-669E82BCCAD4"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev17:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BEE0AF0-3D22-4DE7-9E71-A4469D9CA2EB"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev18:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AAFB199C-1D66-442D-AD7E-414DD339E1D3"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev19:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26322561-2491-4DC7-B974-0B92B61A5BDA"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev20:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6BA6C2B-F2D5-4FF7-B316-C8E99C2B464B"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev21:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "733E4A65-821B-4187-AA3A-1ACD3E882C07"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev22:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B0A0043-33E8-4440-92AC-DDD70EA39535"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev23:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "303205CC-8BDE-47EE-A675-9BA19983139A"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev24:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C088014-47D6-4632-9FB5-2C7B1085B762"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev25:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42CF6057-EB40-4208-9F1E-83213E97987C"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev26:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "966BC23E-B8CE-4F98-B3A6-4B620E8808BE"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev27:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7409CE19-ACC1-4AF4-8C8A-AE2CDBB63D3D"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev28:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17D71CDE-3111-459B-8520-F62E0D5D2972"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev29:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D808ED6-F819-4014-BD24-4537D52DDFB0"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev30:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3792A91-10E9-42D9-B852-37D369D8364E"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev31:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F0BFEEF-8B19-4F71-B7F1-2CC94969616F"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev32:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52003F06-9351-49B6-A3C5-A2B6FC0B9F4D"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev33:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8786112-32AE-4BA5-8D66-D4E2429D3228"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:ox_app_suite:7.10.6:rev34:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A67F528-0248-4E24-A5AB-2995ED7D2600"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@open-xchange.com"
}