CVE-2024-23188
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is required for the vulnerability to trigger. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. We now use safer methods of handling external content when embedding attachment information to the web interface. No publicly available exploits are known.
Los nombres de archivos adjuntos de correo electrónico creados con fines malintencionados podrían utilizarse para ejecutar temporalmente código de script en el contexto de la sesión del navegador del usuario. Se requiere la interacción común del usuario para que se active la vulnerabilidad. Los atacantes podrían realizar solicitudes API maliciosas o extraer información de la cuenta del usuario. Implemente las actualizaciones y lanzamientos de parches proporcionados. Ahora utilizamos métodos más seguros para manejar contenido externo al incorporar información adjunta en la interfaz web. No se conocen exploits disponibles públicamente.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-01-12 CVE Reserved
- 2024-05-06 CVE Published
- 2024-05-07 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2024/May/3 | ||
https://documentation.open-xchange.com/appsuite/releases/8.22 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-Xchange GmbH Search vendor "Open-Xchange GmbH" | OX App Suite Search vendor "Open-Xchange GmbH" for product "OX App Suite" | <= 8.21 Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 8.21" | en |
Affected
|