Skip to main content

Vendor/product archive

open-xchange / open-xchange_appsuite_backend CVEs

Beta · best-effort

14 CVEs tagged to open-xchange / open-xchange_appsuite_backend0 Critical, 2 High, 9 Medium, 3 Low, 0 Unrated.

CVE-2023-26443

Published Aug 2, 2023

Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Excep…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26430

Published Aug 2, 2023

Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEVE extension that are not allowed by A…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26435

Published Jun 20, 2023

It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topolog…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26434

Published Jun 20, 2023

When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26433

Published Jun 20, 2023

When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26432

Published Jun 20, 2023

When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26431

Published Jun 20, 2023

IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26429

Published Jun 20, 2023

Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26428

Published Jun 20, 2023

Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1