CVE-2021-23928: XSS
Published Jan 12, 2021
·Updated
OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.
Affected Software
1 affected component
Open-Xchange Open-Xchange AppSuite<=7.10.3
Event History
Jan 12, 2021
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-23928.
2
What is the severity of CVE-2021-23928?
CVE-2021-23928 has a severity rating of 6.1 (medium).
3
How does the vulnerability in OX App Suite through 7.10.3 occur?
The vulnerability in OX App Suite through 7.10.3 occurs through a cross-site scripting (XSS) attack via the ajax/apps/manifests query string.
4
Which software versions are affected by CVE-2021-23928?
Versions up to and including 7.10.3 of Open-xchange Appsuite are affected by CVE-2021-23928.
5
How can the XSS vulnerability be exploited in OX App Suite?
The XSS vulnerability in OX App Suite can be exploited by crafting a malicious query string in the ajax/apps/manifests URL.