Skip to main content

Vendor/product archive

open-xchange / open-xchange_appsuite CVEs

Beta · best-effort

157 CVEs tagged to open-xchange / open-xchange_appsuite7 Critical, 17 High, 128 Medium, 5 Low, 0 Unrated.

CVE-2021-37403

Published Jul 22, 2021

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative UR…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37402

Published Jul 22, 2021

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26699

Published Jul 22, 2021

OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is u…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26698

Published Jul 22, 2021

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and the dl parameter is used.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28945

Published May 3, 2021

OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://onerror=Function.constructor, in a Notes item.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31935

Published Apr 30, 2021

OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandled in the scheduling view.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31934

Published Apr 30, 2021

OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23929

Published Jan 12, 2021

OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15003

Published Oct 23, 2020

OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12645

Published Aug 31, 2020

OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-50 of 157 CVEsPage 2 of 7