Cross-Site Scripting Vulnerability in Open-Xchange App Suite
CVE-2023-41710

5.4MEDIUM

Key Information:

Vendor
CVE Published:
8 January 2024

What is CVE-2023-41710?

A cross-site scripting vulnerability exists within the Open-Xchange App Suite, where user-defined script code related to an upsell shop URL can be improperly stored and executed. This occurs due to inadequate sanitization when integrating such scripts into the Document Object Model (DOM). Attackers can exploit this flaw to trick users into executing malicious scripts in the context of a trusted domain, potentially compromising sensitive information. Open-Xchange has implemented measures to sanitize this content, but no public exploits have been reported.

Affected Version(s)

OX App Suite 0 <= 7.10.6-rev34

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.