First published: Thu Mar 20 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving 'the aria "tags" for screenreaders at the top bar'.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | =7.4.1 | |
Open-Xchange App Suite Backend | =7.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2077 is classified as a medium severity vulnerability due to its potential for Cross-site scripting (XSS) attacks.
To fix CVE-2014-2077, upgrade Open-Xchange AppSuite to version 7.4.1-rev10 or later, or 7.4.2-rev8 or later.
Yes, CVE-2014-2077 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
CVE-2014-2077 affects Open-Xchange AppSuite versions 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8.
CVE-2014-2077 is a Cross-site scripting (XSS) vulnerability that allows for the injection of malicious scripts.