Document Comments Vulnerability: Filtering User-Defined Content to Prevent Malicious Injections
CVE-2023-41703

6.1MEDIUM

Key Information:

Vendor
CVE Published:
12 February 2024

What is CVE-2023-41703?

A vulnerability exists in the Open-Xchange App Suite where user ID references at mentions within document comments were not adequately sanitized. This lacks the proper filtering and could permit the injection of script code into a user's session while handling a malicious document. To mitigate the risk of exploitation, deploying the provided patches and updates is essential. The recent updates ensure that user-defined content, such as comments and mentions, is filtered effectively to avert potentially harmful operations. No exploits of this vulnerability have been made publicly available as of now.

Affected Version(s)

OX App Suite 0 <= 7.10.6-rev9

OX App Suite 0 <= 8.19

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.