CVE-2020-12644 – OX App Suite / OX Documents XSS / SSRF / Bypass
https://notcve.org/view.php?id=CVE-2020-12644
21 Aug 2020 — OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API. OX App Suite versiones 7.10.3 y anteriores, permiten un ataque de tipo SSRF, relacionado con la API de la cuenta de correo y la API /folder/list OX App Suite and OX Documents suffer from access control bypass, cross site scripting, and improper input validation vulnerabilities. Multiple version ranges are affected. • https://exchange.xforce.ibmcloud.com/vulnerabilities/187116 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2020-12643 – OX App Suite / OX Documents XSS / SSRF / Bypass
https://notcve.org/view.php?id=CVE-2020-12643
21 Aug 2020 — OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address. OX App Suite versiones 7.10.3 y anteriores, presentan un Control de Acceso Incorrecto por medio de una petición de /api/subscriptions para un fragmento que contiene una dirección de correo electrónico OX App Suite and OX Documents suffer from access control bypass, cross site scripting, and improper input validation vulnerabilities. Multiple version ranges are affected. • http://seclists.org/fulldisclosure/2020/Aug/14 • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2020-8541 – OX App Suite / OX Documents 7.10.3 XSS / SSRF / Improper Validation
https://notcve.org/view.php?id=CVE-2020-8541
12 Jun 2020 — OX App Suite through 7.10.3 allows XXE attacks. OX App Suite versiones hasta 7.10.3, permite ataques de tipo XXE OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • https://packetstormsecurity.com/files/158070/OX-App-Suite-OX-Documents-7.10.3-XSS-SSRF-Improper-Validation.html • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2020-8542 – OX App Suite / OX Documents XSS / SSRF / Bypass
https://notcve.org/view.php?id=CVE-2020-8542
12 Jun 2020 — OX App Suite through 7.10.3 allows XSS. OX App Suite versiones hasta 7.10.3, permite un ataque de tipo XSS OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • http://packetstormsecurity.com/files/158932/OX-App-Suite-OX-Documents-XSS-SSRF-Bypass.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-8544 – OX App Suite / OX Documents 7.10.3 XSS / SSRF / Improper Validation
https://notcve.org/view.php?id=CVE-2020-8544
12 Jun 2020 — OX App Suite through 7.10.3 allows SSRF. OX App Suite versiones hasta 7.10.3, permite un ataque de tipo SSRF OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • https://packetstormsecurity.com/files/158070/OX-App-Suite-OX-Documents-7.10.3-XSS-SSRF-Improper-Validation.html • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2020-8543 – OX App Suite / OX Documents 7.10.3 XSS / SSRF / Improper Validation
https://notcve.org/view.php?id=CVE-2020-8543
12 Jun 2020 — OX App Suite through 7.10.3 has Improper Input Validation. OX App Suite versiones hasta 7.10.3, presenta una Comprobación de Entrada Inapropiada OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • https://packetstormsecurity.com/files/158070/OX-App-Suite-OX-Documents-7.10.3-XSS-SSRF-Improper-Validation.html • CWE-20: Improper Input Validation •
CVE-2019-18846 – OX App Suite / OX Documents 7.10.3 XSS / SSRF / Improper Validation
https://notcve.org/view.php?id=CVE-2019-18846
21 Feb 2020 — OX App Suite through 7.10.2 allows SSRF. OX App Suite versiones hasta 7.10.2, permite un ataque de tipo SSRF. OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities. • http://packetstormsecurity.com/files/156474/Open-Xchange-App-Suite-Documents-Server-Side-Request-Forgery.html • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2019-16716 – OX App Suite 7.10.2 Cross Site Scripting / Improper Access Control
https://notcve.org/view.php?id=CVE-2019-16716
02 Jan 2020 — OX App Suite through 7.10.2 has Incorrect Access Control. OX App Suite versiones hasta la versión 7.10.2, presenta un Control de Acceso Incorrecto. Open-Xchange App Suite versions 7.10.2 and below suffer from cross site scripting and improper access control vulnerabilities. • http://packetstormsecurity.com/files/155813/OX-App-Suite-7.10.2-Cross-Site-Scripting-Improper-Access-Control.html • CWE-276: Incorrect Default Permissions •
CVE-2019-16717 – OX App Suite 7.10.2 Cross Site Scripting / Improper Access Control
https://notcve.org/view.php?id=CVE-2019-16717
02 Jan 2020 — OX App Suite through 7.10.2 has XSS. OX App Suite versiones hasta la versión 7.10.2, tiene una vulnerabilidad de tipo XSS. Open-Xchange App Suite versions 7.10.2 and below suffer from cross site scripting and improper access control vulnerabilities. • http://packetstormsecurity.com/files/155813/OX-App-Suite-7.10.2-Cross-Site-Scripting-Improper-Access-Control.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-14227 – Open-Xchange OX App Suite SSRF / XSS / Information Disclosure / Access Controls
https://notcve.org/view.php?id=CVE-2019-14227
14 Oct 2019 — OX App Suite 7.10.1 and 7.10.2 allows XSS. OX App Suite versión 7.10.1 y versión 7.10.2 permite Cross-Site Scripting (XSS). Various Open-Xchange OX App Suite versions suffer from server-side request forgery, cross site scripting, information disclosure, and improper access control vulnerabilities. • http://packetstormsecurity.com/files/154826/Open-Xchange-OX-App-Suite-SSRF-XSS-Information-Disclosure-Access-Controls.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •