Security Flaw in Open-Xchange Upsell Shop Dialog
CVE-2023-29052

5.4MEDIUM

Key Information:

Vendor
CVE Published:
8 January 2024

What is CVE-2023-29052?

A security vulnerability exists within the Open-Xchange AppSuite that allows users to include unsanitized script code in disclaimer texts for upsell shop dialogs. This flaw could enable attackers to create malicious links that trick users into executing harmful scripts within the trust context of the domain. Open-Xchange has implemented content sanitization measures to mitigate this risk, although no publicly known exploits of this vulnerability are currently available.

Affected Version(s)

OX App Suite 0 <= 7.10.6-rev34

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.