Document Comments Vulnerability: Filtering User-Defined Content to Prevent Malicious Injections
CVE-2023-41703
6.1MEDIUM
What is CVE-2023-41703?
A vulnerability exists in the Open-Xchange App Suite where user ID references at mentions within document comments were not adequately sanitized. This lacks the proper filtering and could permit the injection of script code into a user's session while handling a malicious document. To mitigate the risk of exploitation, deploying the provided patches and updates is essential. The recent updates ensure that user-defined content, such as comments and mentions, is filtered effectively to avert potentially harmful operations. No exploits of this vulnerability have been made publicly available as of now.
Affected Version(s)
OX App Suite 0 <= 7.10.6-rev9
OX App Suite 0 <= 8.19