CVE-2021-23929: XSS
Published Jan 12, 2021
·Updated
OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI.
Affected Software
1 affected component
Open-Xchange Open-Xchange AppSuite<=7.10.3
Event History
Jan 12, 2021
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-23929.
2
What is the title of this vulnerability?
The title of this vulnerability is 'OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML ...'.
3
What is the severity of CVE-2021-23929?
The severity of CVE-2021-23929 is medium with a CVSS score of 6.1.
4
Which software is affected by CVE-2021-23929?
Open-xchange Open-xchange Appsuite versions up to and including 7.10.3 are affected by CVE-2021-23929.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by uploading a crafted HTML document with a malicious Content-Disposition header to the ajax/share/<share-token>?delivery=view URI in OX App Suite.