CVE-2013-6997: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents containing "crafted hyperlinks with script URL handlers."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6997?
CVE-2013-6997 has a medium severity rating due to its potential for cross-site scripting exploits.
How do I fix CVE-2013-6997?
To fix CVE-2013-6997, update your Open-Xchange AppSuite to version 7.4.1 or later, which addresses the vulnerabilities.
What types of attacks are associated with CVE-2013-6997?
CVE-2013-6997 is associated with cross-site scripting (XSS) attacks that allow remote attackers to inject malicious scripts.
Which versions of Open-Xchange AppSuite are affected by CVE-2013-6997?
CVE-2013-6997 affects Open-Xchange AppSuite versions 7.4.0 and earlier, as well as specific earlier versions like 6.20.7, 6.22.0, and 7.0.X.
Is CVE-2013-6997 a known issue in Open-Xchange?
Yes, CVE-2013-6997 is a documented vulnerability in Open-Xchange that has been acknowledged and addressed by the developers.