CVE-2019-18846 – OX App Suite / OX Documents 7.10.3 XSS / SSRF / Improper Validation
https://notcve.org/view.php?id=CVE-2019-18846
OX App Suite through 7.10.2 allows SSRF. OX App Suite versiones hasta 7.10.2, permite un ataque de tipo SSRF. OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • http://packetstormsecurity.com/files/156474/Open-Xchange-App-Suite-Documents-Server-Side-Request-Forgery.html http://packetstormsecurity.com/files/158070/OX-App-Suite-OX-Documents-7.10.3-XSS-SSRF-Improper-Validation.html • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2019-16716 – OX App Suite 7.10.2 Cross Site Scripting / Improper Access Control
https://notcve.org/view.php?id=CVE-2019-16716
OX App Suite through 7.10.2 has Incorrect Access Control. OX App Suite versiones hasta la versión 7.10.2, presenta un Control de Acceso Incorrecto. Open-Xchange App Suite versions 7.10.2 and below suffer from cross site scripting and improper access control vulnerabilities. • http://packetstormsecurity.com/files/155813/OX-App-Suite-7.10.2-Cross-Site-Scripting-Improper-Access-Control.html http://seclists.org/fulldisclosure/2020/Jan/7 • CWE-276: Incorrect Default Permissions •
CVE-2019-16717 – OX App Suite 7.10.2 Cross Site Scripting / Improper Access Control
https://notcve.org/view.php?id=CVE-2019-16717
OX App Suite through 7.10.2 has XSS. OX App Suite versiones hasta la versión 7.10.2, tiene una vulnerabilidad de tipo XSS. Open-Xchange App Suite versions 7.10.2 and below suffer from cross site scripting and improper access control vulnerabilities. • http://packetstormsecurity.com/files/155813/OX-App-Suite-7.10.2-Cross-Site-Scripting-Improper-Access-Control.html http://seclists.org/fulldisclosure/2020/Jan/7 https://www.open-xchange.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-14226 – Open-Xchange OX App Suite SSRF / XSS / Information Disclosure / Access Controls
https://notcve.org/view.php?id=CVE-2019-14226
OX App Suite through 7.10.2 has Insecure Permissions. OX App Suite hasta la versión 7.10.2 tiene permisos inseguros. Various Open-Xchange OX App Suite versions suffer from server-side request forgery, cross site scripting, information disclosure, and improper access control vulnerabilities. • http://packetstormsecurity.com/files/154826/Open-Xchange-OX-App-Suite-SSRF-XSS-Information-Disclosure-Access-Controls.html https://seclists.org/fulldisclosure/2019/Oct/25 • CWE-281: Improper Preservation of Permissions •
CVE-2019-14225 – Open-Xchange OX App Suite SSRF / XSS / Information Disclosure / Access Controls
https://notcve.org/view.php?id=CVE-2019-14225
OX App Suite 7.10.1 and 7.10.2 allows SSRF. OX App Suite versión 7.10.1 y versión 7.10.2 permite Server Side Request Forgery (SSRF). Various Open-Xchange OX App Suite versions suffer from server-side request forgery, cross site scripting, information disclosure, and improper access control vulnerabilities. • http://packetstormsecurity.com/files/154826/Open-Xchange-OX-App-Suite-SSRF-XSS-Information-Disclosure-Access-Controls.html https://seclists.org/fulldisclosure/2019/Oct/25 • CWE-918: Server-Side Request Forgery (SSRF) •