CVE-2021-33490: XSS
Published Nov 22, 2021
·Updated
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.5
Event History
Nov 22, 2021
CVE Published
via MITRE·07:39 AM
Data Sourced
via MITRE·07:39 AM
Description
Frequently Asked Questions
1
What is CVE-2021-33490?
CVE-2021-33490 is a vulnerability in OX App Suite versions up to and including 7.10.5 that allows cross-site scripting (XSS) attacks through a crafted snippet in a shared mail signature.
2
How does CVE-2021-33490 affect OX App Suite?
CVE-2021-33490 affects OX App Suite versions up to and including 7.10.5.
3
What is the severity of CVE-2021-33490?
CVE-2021-33490 has a severity rating of medium with a CVSS score of 6.1.
4
How can XSS attacks occur in OX App Suite?
XSS attacks can occur in OX App Suite through a crafted snippet in a shared mail signature.
5
Is there a fix for CVE-2021-33490?
To fix CVE-2021-33490, users should update OX App Suite to a version above 7.10.5.