CVE-2020-12644
Published Aug 31, 2020OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
Vendor/product archive
157 CVEs tagged to open-xchange / open-xchange_appsuite — 7 Critical, 17 High, 128 Medium, 5 Low, 0 Unrated.
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.
OX App Suite through 7.10.3 allows SSRF.
OX App Suite through 7.10.3 has Improper Input Validation.
OX App Suite through 7.10.3 allows XSS.
OX App Suite through 7.10.3 allows XXE attacks.
OX App Suite through 7.10.2 allows SSRF.
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read…
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly o…
OX App Suite through 7.10.2 has XSS.
OX App Suite through 7.10.2 has Incorrect Access Control.
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbit…
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbit…
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject a…
OX App Suite 7.10.1 and 7.10.2 allows XSS.
OX App Suite through 7.10.2 has Insecure Permissions.
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
OX App Suite 7.10.1 and earlier has Insecure Permissions.
OX App Suite 7.10.0 to 7.10.2 allows XSS.
OX App Suite 7.10.1 allows Content Spoofing.
OX App Suite 7.10.1 and earlier allows Information Exposure.
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).