CVE-2015-7385: XSS
Published Nov 19, 2015
·Updated
Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject arbitrary web script or HTML via the uid field in a PGP public key, which is not properly handled in "Guard PGP Settings."
Affected Software
1 affected component
Open-Xchange OX Guard<=2.0.0
Event History
Nov 19, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7385?
CVE-2015-7385 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2015-7385?
To fix CVE-2015-7385, upgrade Open-Xchange OX Guard to version 2.0.0-rev11 or later.
3
What type of vulnerability is CVE-2015-7385?
CVE-2015-7385 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts.
4
Which versions of Open-Xchange OX Guard are affected by CVE-2015-7385?
CVE-2015-7385 affects all versions of Open-Xchange OX Guard prior to 2.0.0-rev11.
5
What can attackers accomplish with CVE-2015-7385?
Attackers can exploit CVE-2015-7385 to inject malicious web scripts via the uid field in a PGP public key.