CVE-2013-1646: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary web script or HTML via (1) invalid JSON data in a mail-sending POST request, (2) an arbitrary parameter to servlet/TestServlet, (3) a javascript: URL in a standalone-mode action to a UWA module, (4) an infostore attachment, (5) JavaScript code in a contact image, (6) an RSS feed, or (7) a signature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1646?
CVE-2013-1646 has a moderate severity rating due to its multiple cross-site scripting vulnerabilities that can be exploited by remote attackers.
How do I fix CVE-2013-1646?
To fix CVE-2013-1646, upgrade Open-Xchange Server to version 6.20.7 rev14 or later, 6.22.0 rev13 or later, or 6.22.1 rev14 or later.
What are the potential impacts of CVE-2013-1646?
The potential impacts of CVE-2013-1646 include the ability for attackers to inject arbitrary web scripts or HTML, leading to data theft or account compromise.
Which versions of Open-Xchange Server are affected by CVE-2013-1646?
CVE-2013-1646 affects Open-Xchange Server versions prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14.
Who can exploit the vulnerabilities in CVE-2013-1646?
Remote attackers can exploit the vulnerabilities in CVE-2013-1646 using invalid JSON data in a mail-sending POST request or by manipulating parameters in certain servlets.