CVE-2023-41708
Estado: ModificadaMedia (5.4)—
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
- CWE-79
Referencias
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0007.json
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf
- http://seclists.org/fulldisclosure/2024/Feb/10
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0007.json
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-41708",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-41708",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-02-12T15:57:31.673557Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@open-xchange.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security@open-xchange.com",
"affectedData": [
{
"vendor": "Open-Xchange GmbH",
"modules": [
"frontend"
],
"product": "OX App Suite",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "7.10.6-rev38"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-02-12T09:15:11.470",
"references": [
{
"url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0007.json",
"tags": [
"Vendor Advisory"
],
"source": "security@open-xchange.com"
},
{
"url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf",
"tags": [
"Vendor Advisory"
],
"source": "security@open-xchange.com"
},
{
"url": "http://seclists.org/fulldisclosure/2024/Feb/10",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0007.json",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@open-xchange.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "References to the \"app loader\" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known."
},
{
"lang": "es",
"value": "Las referencias a la funcionalidad \"cargador de aplicaciones\" podrían contener redireccionamientos a ubicaciones inesperadas. Los atacantes podrían falsificar referencias de aplicaciones que eluden las salvaguardas existentes para inyectar código de script malicioso. Implemente las actualizaciones y lanzamientos de parches proporcionados. Las referencias a aplicaciones ahora se controlan de manera más estricta para evitar referencias relativas. No se conocen exploits disponibles públicamente."
}
],
"lastModified": "2026-06-17T06:22:39.593",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59D4F30E-2F52-4948-9C69-C57472833C79",
"versionEndExcluding": "7.10.6"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A144D75D-60A8-4EE0-813C-F658C626B2AA"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6069:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DA66230-DE02-4881-A893-E9E78286B157"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6073:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "955F3DFB-6479-4867-B62A-82730DBEB498"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6080:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "327D1B56-0D05-4D99-91D4-CC1F0AC32972"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6085:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0CD0684-C431-47F8-A2F4-1936D5C5A72B"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6093:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAA6A4A7-C1EE-4716-9F4D-2FF4C4D5FEC8"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6102:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0968764-CCEE-47A7-9111-E106D887DA43"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6112:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16589FBB-F0CD-4041-8141-5C89FCCA72AF"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6121:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CB877EE-A5FE-4FF7-9D21-5C1CFA7343D4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6133:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DF5FB90-8D6D-4F99-B454-411B1DFFA630"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6138:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F58876B9-6C2E-4048-A793-B441A84E86F5"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6141:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5F177CB-CC45-45A0-9D02-C14A13ECC7A3"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6146:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A89A4192-54E9-4899-8C7B-6C7F7E650D5C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6147:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2DC1357-9CD5-415F-A190-2F3F4498EF96"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6148:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D78ACF64-2802-44DD-AF7A-1BD5EA7F9908"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6150:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8F675FA-1684-413A-B1BE-1C5434AC2862"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6156:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3F1FDC3-35B2-4BDB-A685-75BC72588179"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6161:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B1E509D-2F41-4296-86D2-6BD71783060F"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6166:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC93EA37-F341-45EC-B651-4F326FB8C613"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6173:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A4DB8A6-1702-462C-BFCB-39F91D2EFCE1"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6176:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC0AEFDB-D033-47FC-93FC-8652F922BB8C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6178:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5354768-6527-43C2-B492-A8C14AB4E784"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6189:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D83F26D1-B8C6-4114-81EC-810DD5412DC8"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6194:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9EBC010-9963-4636-96F7-A121FCF755A7"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6199:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F626D64B-C301-4CD8-94B4-48689BD3F29C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6204:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E32810C-7B35-42F1-BCA5-E10C02BE2215"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6205:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6539D059-8614-4C26-93C4-C2DDCC5D35E2"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6209:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E359EE75-A2F9-479B-B757-CAE1064AB8F4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6210:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BCABDEF-D292-406E-B53C-AFF22484E916"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6214:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABE8872C-B1DD-4A45-8EF8-E8C355CA6C54"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6215:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44B20B83-833A-4C68-8693-365BD046C157"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6216:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E254E6D1-D18E-4A2A-A2FF-7D03F39E65DD"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6218:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F0C5E53-4D15-425A-B4CF-5869353724BF"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6219:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F4BF5F1-F316-4BAC-83E0-DEAC8C50754E"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6220:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CDD03A8-5B86-4B87-9C29-6C967261C5C0"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6227:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6071E15F-4D59-41DC-A4D4-7D1AA392A1F2"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6230:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C72C1CEB-7BF7-4A5F-B2E9-397F86CCBF4E"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6233:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B0F0218-4224-4084-B38D-9719D3782C03"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6235:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFC41329-1AD6-4575-A22D-977EC5539DA4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6236:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "217A06B7-0823-4508-BC0C-AD792BA88F7B"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6239:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "246E98B2-A6C8-4410-AA6A-7E81EE8C5E76"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6241:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74D1EC02-D009-45DA-B1EC-2219E0F0183C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6243:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F56A261-EC62-423C-B487-35EA9D4A83FB"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6245:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D295E160-C87A-498D-AB0E-BA1E50825249"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6248:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A30BE138-D745-4F0E-AAE4-202A1C769C85"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6249:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7CF4FCB9-7360-4ABB-95FB-0239CDC8D3AD"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6250:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "465DD666-3499-4911-A1DF-6BAAFCCFA006"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6251:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F18CEDC-5D7A-4496-8B5E-59EBEA4362BD"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6255:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C1DE547-F217-4518-AD90-3607AE21F6ED"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@open-xchange.com"
}