CVE-2018-5754
OX App Suite 7.8.4 - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.
Vulnerabilidad de Cross-Site Scripting (XSS) en el componente office-web en Open-Xchange OX App Suite en versiones anteriores a la 7.8.3-rev12 y versiones 7.8.4 anteriores a la 7.8.4-rev9 permite que atacantes remoto inyecten scripts web o HTML arbitrarios mediante un archivo de presentación manipulado. Esto está relacionado con la copia de contenidos al portapapeles.
OX App Suite versions 7.8.4 and below suffer from cross site scripting, improper privilege management, content spoofing, server-side request forgery, and path traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-17 CVE Reserved
- 2018-06-08 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | <= 7.8.3 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version " <= 7.8.3" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.3 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.3" | rev10 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.3 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.3" | rev11 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.3 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.3" | rev5 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.3 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.3" | rev6 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.3 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.3" | rev8 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.3 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.3" | rev9 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.4 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.4" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.4 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.4" | rev3 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.4 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.4" | rev4 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.4 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.4" | rev5 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.4 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.4" | rev6 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.4 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.4" | rev7 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.8.4 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.8.4" | rev8 |
Affected
|