Vulnerability CVE-2018-9997


Published: 2018-07-05

Description:
Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute in an HTML page with data-toggle gadgets.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
OX App Suite 7.8.4 XSS / XML Injection / Information Disclosure
Secator
02.07.2018
Low
Open-Xchange OX Guard Cross Site Scripting / Signature Validation
Hanno Boeck
17.08.2019

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Open-xchange -> Open-xchange appsuite 

 References:
http://packetstormsecurity.com/files/154127/Open-Xchange-OX-Guard-Cross-Site-Scripting-Signature-Validation.html
http://seclists.org/fulldisclosure/2018/Jul/12
http://www.securitytracker.com/id/1041213

Copyright 2024, cxsecurity.com

 

Back to Top