Page 11 of 62 results (0.008 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 2

OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call. OX App Suite versiones hasta 7.10.5, presenta un Control de Acceso Incorrecto para la recuperación de la información de la sesión por medio de la acción de rampa de la llamada a la API de inicio de sesión OX App Suite versions 7.10.5 and below suffer from cross site scripting and information disclosure vulnerabilities. • http://packetstormsecurity.com/files/165038/OX-App-Suite-7.10.5-Cross-Site-Scripting-Information-Disclosure.html https://seclists.org/fulldisclosure/2021/Nov/43 https://www.open-xchange.com • CWE-287: Improper Authentication •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message. OX App Suite versiones hasta 7.10.5, permite un ataque de tipo XSS por medio del atributo alt de un elemento IMG en un mensaje de correo electrónico truncado OX App Suite versions 7.10.5 and below suffer from cross site scripting and information disclosure vulnerabilities. • http://packetstormsecurity.com/files/165038/OX-App-Suite-7.10.5-Cross-Site-Scripting-Information-Disclosure.html https://seclists.org/fulldisclosure/2021/Nov/43 https://www.open-xchange.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 3

OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL. OX App Suite versiones hasta 7.10.5, permite un ataque de tipo XSS por medio de un fragmento diseñado que presenta una referencia al cargador de aplicaciones dentro de una URL del cargador de aplicaciones OX App Suite versions 7.10.5 and below suffer from cross site scripting and information disclosure vulnerabilities. • http://packetstormsecurity.com/files/165038/OX-App-Suite-7.10.5-Cross-Site-Scripting-Information-Disclosure.html http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html http://seclists.org/fulldisclosure/2021/Nov/43 http://seclists.org/fulldisclosure/2022/Jul/11 https://www.open-xchange.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

OX App Suite 7.10.5 allows XSS via an OX Chat system message. OX App Suite versión 7.10.5, permite un ataque de tipo XSS por medio de un mensaje del sistema OX Chat OX App Suite and OX Documents suffer from cross site scripting, code injection, path traversal, and input validation vulnerabilities. Most of these issues affect 7.10.5 and below with one affecting 7.10.4 and below. • http://packetstormsecurity.com/files/165028/OX-App-Suite-Ox-Documents-7.10.x-XSS-Code-Injection-Traversal.html https://open-xchange.com https://seclists.org/fulldisclosure/2021/Nov/42 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering. OX App Suite versión 7.10.5, permite un ataque de tipo XSS por medio de un título de sala de OX Chat durante la renderización de la escritura OX App Suite and OX Documents suffer from cross site scripting, code injection, path traversal, and input validation vulnerabilities. Most of these issues affect 7.10.5 and below with one affecting 7.10.4 and below. • http://packetstormsecurity.com/files/165028/OX-App-Suite-Ox-Documents-7.10.x-XSS-Code-Injection-Traversal.html https://open-xchange.com https://seclists.org/fulldisclosure/2021/Nov/42 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •