Cross-Site Scripting Vulnerability in Open-Xchange App Suite
CVE-2023-29049

5.4MEDIUM

Key Information:

Vendor
CVE Published:
8 January 2024

What is CVE-2023-29049?

An input validation vulnerability exists in the upsell widget of the Open-Xchange App Suite portal page, where attackers can exploit this weakness to inject arbitrary script code. If an attacker successfully induces a user to interact with a compromised account or gains temporary access to a legitimate account, they could execute persistent code within a trusted domain. Measures have been implemented to sanitize user input for this widget, effectively preventing execution of malicious content. At this time, there are no known public exploits that actively leverage this vulnerability.

Affected Version(s)

OX App Suite 0 <= 7.10.6-rev33

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.