Cross-Site Scripting Vulnerability in Open-Xchange App Suite
CVE-2023-29049
5.4MEDIUM
What is CVE-2023-29049?
An input validation vulnerability exists in the upsell widget of the Open-Xchange App Suite portal page, where attackers can exploit this weakness to inject arbitrary script code. If an attacker successfully induces a user to interact with a compromised account or gains temporary access to a legitimate account, they could execute persistent code within a trusted domain. Measures have been implemented to sanitize user input for this widget, effectively preventing execution of malicious content. At this time, there are no known public exploits that actively leverage this vulnerability.
Affected Version(s)
OX App Suite 0 <= 7.10.6-rev33