Email CID References Vulnerability: Malicious Script Code Injection
CVE-2023-41704

6.1MEDIUM

Key Information:

Vendor
CVE Published:
12 February 2024

What is CVE-2023-41704?

A vulnerability exists in Open-Xchange App Suite that could allow attackers to exploit CID references in emails, enabling the injection of malicious scripts that may bypass the sanitization engine. When users interact with such emails, their sessions could be compromised through these injected scripts. To mitigate this risk, it is essential to apply the latest patches and updates provided by Open-Xchange. Recent improvements in CID handling ensure that resulting content is thoroughly checked for any malicious code attempts.

Affected Version(s)

OX App Suite 0 <= 7.10.6-rev55

OX App Suite 0 <= 7.6.3-rev71

OX App Suite 0 <= 8.20

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.