First published: Tue Jan 12 2021(Updated: )
OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-xchange Open-xchange Appsuite | <=7.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-23934.
CVE-2021-23934 has a severity rating of 6.1, which is considered medium.
The affected software for CVE-2021-23934 is Open-xchange Appsuite version up to and including 7.10.3.
The vulnerability manifests as a cross-site scripting (XSS) issue that can be exploited through a contact whose name contains JavaScript code.
Yes, you can find more information about CVE-2021-23934 at the following link: https://packetstormsecurity.com/files/160853/OX-App-Suite-OX-Documents-7.10.x-XSS-SSRF.html