Email CID References Vulnerability: Malicious Script Code Injection
CVE-2023-41704
6.1MEDIUM
What is CVE-2023-41704?
A vulnerability exists in Open-Xchange App Suite that could allow attackers to exploit CID references in emails, enabling the injection of malicious scripts that may bypass the sanitization engine. When users interact with such emails, their sessions could be compromised through these injected scripts. To mitigate this risk, it is essential to apply the latest patches and updates provided by Open-Xchange. Recent improvements in CID handling ensure that resulting content is thoroughly checked for any malicious code attempts.
Affected Version(s)
OX App Suite 0 <= 7.10.6-rev55
OX App Suite 0 <= 7.6.3-rev71
OX App Suite 0 <= 8.20