CVE-2023-41708
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.
Las referencias a la funcionalidad "cargador de aplicaciones" podrían contener redireccionamientos a ubicaciones inesperadas. Los atacantes podrían falsificar referencias de aplicaciones que eluden las salvaguardas existentes para inyectar código de script malicioso. Implemente las actualizaciones y lanzamientos de parches proporcionados. Las referencias a aplicaciones ahora se controlan de manera más estricta para evitar referencias relativas. No se conocen exploits disponibles públicamente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-08-30 CVE Reserved
- 2024-02-12 CVE Published
- 2024-08-02 CVE Updated
- 2025-01-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-Xchange GmbH Search vendor "Open-Xchange GmbH" | OX App Suite Search vendor "Open-Xchange GmbH" for product "OX App Suite" | <= 7.10.6-rev38 Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 7.10.6-rev38" | en |
Affected
|