CVE-2021-33492: XSS
Published Nov 22, 2021
·Updated
OX App Suite 7.10.5 allows XSS via an OX Chat room name.
Affected Software
1 affected component
Open-Xchange Ox App Suite=7.10.5
Event History
Nov 22, 2021
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
Description
Frequently Asked Questions
1
What is CVE-2021-33492?
CVE-2021-33492 is a vulnerability in OX App Suite 7.10.5 that allows cross-site scripting (XSS) attacks via an OX Chat room name.
2
How severe is CVE-2021-33492?
CVE-2021-33492 has a severity score of 6.1, which is considered medium.
3
How does CVE-2021-33492 affect OX App Suite?
CVE-2021-33492 affects OX App Suite version 7.10.5.
4
What is the Common Weakness Enumeration (CWE) for CVE-2021-33492?
The CWE for CVE-2021-33492 is CWE-79, which is the code for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2021-33492?
To fix CVE-2021-33492, it is recommended to update to a newer version of OX App Suite that includes a patch for the vulnerability.