CVE-2023-41704
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.
Se puede abusar del procesamiento de referencias de CID en el correo electrónico para inyectar código de script malicioso que pasa el motor de sanitización. Se podría inyectar código de script malicioso en las sesiones de un usuario al interactuar con correos electrónicos. Implemente las actualizaciones y lanzamientos de parches proporcionados. Se ha mejorado la gestión de CID y se comprueba el contenido resultante en busca de contenido malicioso. No se conocen exploits disponibles públicamente.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-08-30 CVE Reserved
- 2024-02-12 CVE Published
- 2024-08-22 CVE Updated
- 2025-01-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-Xchange GmbH Search vendor "Open-Xchange GmbH" | OX App Suite Search vendor "Open-Xchange GmbH" for product "OX App Suite" | <= 7.10.6-rev55 Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 7.10.6-rev55" | en |
Affected
| ||||||
Open-Xchange GmbH Search vendor "Open-Xchange GmbH" | OX App Suite Search vendor "Open-Xchange GmbH" for product "OX App Suite" | <= 7.6.3-rev71 Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 7.6.3-rev71" | en |
Affected
| ||||||
Open-Xchange GmbH Search vendor "Open-Xchange GmbH" | OX App Suite Search vendor "Open-Xchange GmbH" for product "OX App Suite" | <= 8.20 Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 8.20" | en |
Affected
|