CVE-2021-23934: XSS
Published Jan 12, 2021
·Updated
OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.
Affected Software
1 affected component
Open-Xchange Open-Xchange AppSuite<=7.10.3
Event History
Jan 12, 2021
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-23934.
2
What is the severity of CVE-2021-23934?
CVE-2021-23934 has a severity rating of 6.1, which is considered medium.
3
What is the affected software for CVE-2021-23934?
The affected software for CVE-2021-23934 is Open-xchange Appsuite version up to and including 7.10.3.
4
How does the vulnerability manifest?
The vulnerability manifests as a cross-site scripting (XSS) issue that can be exploited through a contact whose name contains JavaScript code.
5
Are there any references related to this vulnerability?
Yes, you can find more information about CVE-2021-23934 at the following link: https://packetstormsecurity.com/files/160853/OX-App-Suite-OX-Documents-7.10.x-XSS-SSRF.html