CVE-2021-23935: XSS
Published Jan 12, 2021
·Updated
OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.
Affected Software
1 affected component
Open-Xchange Open-Xchange AppSuite<=7.10.3
Event History
Jan 12, 2021
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
Description
Frequently Asked Questions
1
What is CVE-2021-23935?
CVE-2021-23935 is a vulnerability in OX App Suite through version 7.10.4 that allows cross-site scripting (XSS) attacks via an appointment with JavaScript code in the location field.
2
How severe is CVE-2021-23935?
CVE-2021-23935 has a severity value of 6.1, which is considered medium.
3
What is the affected software of CVE-2021-23935?
The affected software of CVE-2021-23935 is OX App Suite up to and including version 7.10.3.
4
How can CVE-2021-23935 be exploited?
CVE-2021-23935 can be exploited by creating an appointment with JavaScript code in the location field.
5
How can CVE-2021-23935 be mitigated?
To mitigate CVE-2021-23935, it is recommended to update OX App Suite to version 7.10.4 or later.