Skip to main content

Vendor/product archive

open-xchange / open-xchange_appsuite_office CVEs

Beta · best-effort

4 CVEs tagged to open-xchange / open-xchange_appsuite_office0 Critical, 2 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2023-26442

Published Aug 2, 2023

In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricte…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26440

Published Aug 2, 2023

The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups.…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26439

Published Aug 2, 2023

The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a l…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1