First published: Thu Apr 17 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | <=7.2.2 | |
Open-Xchange App Suite Backend | =7.2.0 | |
Open-Xchange App Suite Backend | =7.2.1 | |
Open-Xchange App Suite Backend | =7.4.1 | |
Open-Xchange App Suite Backend | =7.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2393 is classified as a moderate severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2014-2393, update Open-Xchange AppSuite to version 7.4.1-rev11 or later, or 7.4.2-rev13 or later.
The impacts of CVE-2014-2393 include the possibility for remote attackers to inject arbitrary web scripts or HTML, leading to compromised user sessions or site content.
Open-Xchange AppSuite versions 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13, as well as all versions prior to 7.2.2, are affected by CVE-2014-2393.
Yes, CVE-2014-2393 allows for user input to be improperly handled, creating a vector for cross-site scripting attacks.