First published: Thu Jun 08 2017(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | <=7.4.2 | |
Open-Xchange App Suite Backend | =7.6.0 | |
Open-Xchange App Suite Backend | =7.6.1 | |
Open-xchange Open-xchange Server | =6.0 | |
Open-xchange Open-xchange Server | =6.22.12 | |
Open-xchange Open-xchange Server | =6.22.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1588 has been classified with a medium severity level due to its potential impact on users through cross-site scripting attacks.
To fix CVE-2015-1588, update your Open-Xchange Server to versions 7.4.2-rev43 or higher, or 7.6.0-rev38 and above.
CVE-2015-1588 affects Open-Xchange Server 6 and OX AppSuite versions prior to 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.
Yes, if exploited, CVE-2015-1588 can allow attackers to execute scripts in the context of a user's browser, potentially leading to data theft.
You can determine your vulnerability to CVE-2015-1588 by checking the version of your Open-Xchange software against the affected versions.