First published: Mon May 03 2021(Updated: )
OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://onerror=Function.constructor, in a Notes item.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-xchange Open-xchange Appsuite | <=7.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-28945.
The severity of CVE-2020-28945 is medium, with a CVSS score of 6.1.
OX App Suite versions up to and including 7.10.4 are affected by CVE-2020-28945.
CVE-2020-28945 allows XSS attacks by allowing crafted content to reach an undocumented feature.
The vendor has not provided a specific patch or fix for CVE-2020-28945. It is recommended to update to a patched version of OX App Suite if available, or follow any mitigation steps provided by the vendor.