CVE-2014-2393: XSS
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2393?
CVE-2014-2393 is classified as a moderate severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2014-2393?
To fix CVE-2014-2393, update Open-Xchange AppSuite to version 7.4.1-rev11 or later, or 7.4.2-rev13 or later.
What are the potential impacts of CVE-2014-2393?
The impacts of CVE-2014-2393 include the possibility for remote attackers to inject arbitrary web scripts or HTML, leading to compromised user sessions or site content.
Which versions are affected by CVE-2014-2393?
Open-Xchange AppSuite versions 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13, as well as all versions prior to 7.2.2, are affected by CVE-2014-2393.
Is user input vulnerability present in CVE-2014-2393?
Yes, CVE-2014-2393 allows for user input to be improperly handled, creating a vector for cross-site scripting attacks.