CVE-2021-23933: XSS
Published Jan 12, 2021
·Updated
OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
Affected Software
1 affected component
Open-Xchange Open-Xchange AppSuite<=7.10.3
Event History
Jan 12, 2021
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of OX App Suite XSS vulnerability?
The vulnerability ID is CVE-2021-23933.
2
What is the severity of CVE-2021-23933?
The severity of CVE-2021-23933 is medium with a CVSS score of 6.1.
3
How does the vulnerability occur in OX App Suite?
The vulnerability occurs in OX App Suite through 7.10.4 and allows XSS via JavaScript in a Note referenced by a mail:// URL.
4
Which version of OX App Suite is affected by the XSS vulnerability?
The versions up to and including 7.10.3 of OX App Suite are affected by the XSS vulnerability.
5
Is there a fix available for CVE-2021-23933?
Yes, upgrading to a version higher than 7.10.4 of OX App Suite will fix the XSS vulnerability.