CVE-2020-12646: XSS
Published Aug 31, 2020
·Updated
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
Affected Software
1 affected component
Open-Xchange Open-Xchange AppSuite<=7.10.3
Event History
Aug 31, 2020
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-12646.
2
What is the title of the vulnerability?
The title of the vulnerability is 'OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript text/rdf or a PDF document.'
3
What is the severity of CVE-2020-12646?
The severity of CVE-2020-12646 is medium with a severity value of 5.4.
4
How does OX App Suite 7.10.3 and earlier allow XSS?
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
5
What is the affected software for CVE-2020-12646?
The affected software for CVE-2020-12646 is OX App Suite version 7.10.3 and earlier.
6
Is there a fix available?
To fix CVE-2020-12646, it is recommended to upgrade to a version higher than 7.10.3.
7
What is the Common Weakness Enumeration (CWE) number for this vulnerability?
The Common Weakness Enumeration (CWE) number for CVE-2020-12646 is CWE-79.