Cross-Site Scripting Vulnerability in Open-Xchange App Suite
CVE-2023-41710
5.4MEDIUM
What is CVE-2023-41710?
A cross-site scripting vulnerability exists within the Open-Xchange App Suite, where user-defined script code related to an upsell shop URL can be improperly stored and executed. This occurs due to inadequate sanitization when integrating such scripts into the Document Object Model (DOM). Attackers can exploit this flaw to trick users into executing malicious scripts in the context of a trusted domain, potentially compromising sensitive information. Open-Xchange has implemented measures to sanitize this content, but no public exploits have been reported.
Affected Version(s)
OX App Suite 0 <= 7.10.6-rev34