CVE-2023-41703
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.
Las referencias de identificación de usuario en las menciones en los comentarios del documento no se sanitizaron correctamente. Se podría inyectar código de script en la sesión de un usuario cuando se trabaja con un documento malicioso. Implemente las actualizaciones y lanzamientos de parches proporcionados. El contenido definido por el usuario, como comentarios y menciones, ahora se filtra para evitar contenido potencialmente malicioso. No se conocen exploits disponibles públicamente.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-08-30 CVE Reserved
- 2024-02-12 CVE Published
- 2024-08-02 CVE Updated
- 2025-01-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-Xchange GmbH Search vendor "Open-Xchange GmbH" | OX App Suite Search vendor "Open-Xchange GmbH" for product "OX App Suite" | <= 7.10.6-rev9 Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 7.10.6-rev9" | en |
Affected
| ||||||
Open-Xchange GmbH Search vendor "Open-Xchange GmbH" | OX App Suite Search vendor "Open-Xchange GmbH" for product "OX App Suite" | <= 8.19 Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 8.19" | en |
Affected
|