Page 5 of 151 results (0.037 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 1

19 Oct 2020 — OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access). OX App Suite versiones hasta 7.10.3, permite una Exposición de Información porque un usuario puede obtener la dirección IP y la cadena User-Agent de un usuario diferente (por medio de la API de sesión durante el acceso a la Unidad compartida) OX App Suite and OX Documents versions 7.10.3 and some prior versions suffer fro... • https://seclists.org/fulldisclosure/2020/Oct/20 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 3

19 Oct 2020 — OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. OX App Suite versiones hasta 7.10.3, permite un ataque de tipo SSRF por medio de la API de mensajes /ajax/messaging/message OX App Suite and OX Documents versions 7.10.3 and some prior versions suffer from information exposure, server-side request forgery, and cross site scripting vulnerabilities. • https://github.com/skr0x1c0/SSRF-CVE-2020-15002 • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

21 Aug 2020 — OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption. OX App Suite versiones 7.10.1 hasta 7.10.3, presenta una comprobación de entrada inapropiada para los límites de tarifas con un encabezado User-Agent diseñado, avisos de vacaciones falsificados y consumo de memoria de /apps/load OX App Suite and OX Documents suffer from access control bypass, cross site scripting, and improper input valida... • https://seclists.org/fulldisclosure/2020/Aug/14 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

21 Aug 2020 — OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. OX App Suite versiones 7.10.3 y anteriores, permiten un ataque de tipo XSS por medio de texto/x-javascript, texto/rdf o un documento PDF OX App Suite and OX Documents suffer from access control bypass, cross site scripting, and improper input validation vulnerabilities. Multiple version ranges are affected. • https://exchange.xforce.ibmcloud.com/vulnerabilities/187114 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

21 Aug 2020 — OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API. OX App Suite versiones 7.10.3 y anteriores, permiten un ataque de tipo SSRF, relacionado con la API de la cuenta de correo y la API /folder/list OX App Suite and OX Documents suffer from access control bypass, cross site scripting, and improper input validation vulnerabilities. Multiple version ranges are affected. • https://exchange.xforce.ibmcloud.com/vulnerabilities/187116 • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

21 Aug 2020 — OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address. OX App Suite versiones 7.10.3 y anteriores, presentan un Control de Acceso Incorrecto por medio de una petición de /api/subscriptions para un fragmento que contiene una dirección de correo electrónico OX App Suite and OX Documents suffer from access control bypass, cross site scripting, and improper input validation vulnerabilities. Multiple version ranges are affected. • http://seclists.org/fulldisclosure/2020/Aug/14 • CWE-639: Authorization Bypass Through User-Controlled Key •

CVSS: 6.5EPSS: 0%CPEs: 16EXPL: 0

12 Jun 2020 — OX App Suite through 7.10.3 allows XXE attacks. OX App Suite versiones hasta 7.10.3, permite ataques de tipo XXE OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • https://packetstormsecurity.com/files/158070/OX-App-Suite-OX-Documents-7.10.3-XSS-SSRF-Improper-Validation.html • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 5.4EPSS: 0%CPEs: 54EXPL: 0

12 Jun 2020 — OX App Suite through 7.10.3 allows XSS. OX App Suite versiones hasta 7.10.3, permite un ataque de tipo XSS OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • http://packetstormsecurity.com/files/158932/OX-App-Suite-OX-Documents-XSS-SSRF-Bypass.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 125EXPL: 0

12 Jun 2020 — OX App Suite through 7.10.3 allows SSRF. OX App Suite versiones hasta 7.10.3, permite un ataque de tipo SSRF OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • https://packetstormsecurity.com/files/158070/OX-App-Suite-OX-Documents-7.10.3-XSS-SSRF-Improper-Validation.html • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 7.5EPSS: 0%CPEs: 125EXPL: 0

12 Jun 2020 — OX App Suite through 7.10.3 has Improper Input Validation. OX App Suite versiones hasta 7.10.3, presenta una Comprobación de Entrada Inapropiada OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • https://packetstormsecurity.com/files/158070/OX-App-Suite-OX-Documents-7.10.3-XSS-SSRF-Improper-Validation.html • CWE-20: Improper Input Validation •