First published: Thu Jul 22 2021(Updated: )
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | =7.10.3 | |
Open-Xchange App Suite Backend | =7.10.3-patch_release5547 | |
Open-Xchange App Suite Backend | =7.10.3-patch_release5572 | |
Open-Xchange App Suite Backend | =7.10.3-patch_release5623 | |
Open-Xchange App Suite Backend | =7.10.3-patch_release5653 | |
Open-Xchange App Suite Backend | =7.10.3-patch_release5677 | |
Open-Xchange App Suite Backend | =7.10.3-patch_release5720 | |
Open-Xchange App Suite Backend | =7.10.3-rev1 | |
Open-Xchange App Suite Backend | =7.10.3-rev10 | |
Open-Xchange App Suite Backend | =7.10.3-rev11 | |
Open-Xchange App Suite Backend | =7.10.3-rev12 | |
Open-Xchange App Suite Backend | =7.10.3-rev13 | |
Open-Xchange App Suite Backend | =7.10.3-rev14 | |
Open-Xchange App Suite Backend | =7.10.3-rev15 | |
Open-Xchange App Suite Backend | =7.10.3-rev16 | |
Open-Xchange App Suite Backend | =7.10.3-rev17 | |
Open-Xchange App Suite Backend | =7.10.3-rev18 | |
Open-Xchange App Suite Backend | =7.10.3-rev19 | |
Open-Xchange App Suite Backend | =7.10.3-rev2 | |
Open-Xchange App Suite Backend | =7.10.3-rev20 | |
Open-Xchange App Suite Backend | =7.10.3-rev21 | |
Open-Xchange App Suite Backend | =7.10.3-rev22 | |
Open-Xchange App Suite Backend | =7.10.3-rev23 | |
Open-Xchange App Suite Backend | =7.10.3-rev24 | |
Open-Xchange App Suite Backend | =7.10.3-rev25 | |
Open-Xchange App Suite Backend | =7.10.3-rev26 | |
Open-Xchange App Suite Backend | =7.10.3-rev27 | |
Open-Xchange App Suite Backend | =7.10.3-rev28 | |
Open-Xchange App Suite Backend | =7.10.3-rev29 | |
Open-Xchange App Suite Backend | =7.10.3-rev3 | |
Open-Xchange App Suite Backend | =7.10.3-rev30 | |
Open-Xchange App Suite Backend | =7.10.3-rev31 | |
Open-Xchange App Suite Backend | =7.10.3-rev4 | |
Open-Xchange App Suite Backend | =7.10.3-rev5 | |
Open-Xchange App Suite Backend | =7.10.3-rev6 | |
Open-Xchange App Suite Backend | =7.10.3-rev7 | |
Open-Xchange App Suite Backend | =7.10.3-rev8 | |
Open-Xchange App Suite Backend | =7.10.3-rev9 | |
Open-Xchange App Suite Backend | =7.10.4 | |
Open-Xchange App Suite Backend | =7.10.4-rev1 | |
Open-Xchange App Suite Backend | =7.10.4-rev10 | |
Open-Xchange App Suite Backend | =7.10.4-rev11 | |
Open-Xchange App Suite Backend | =7.10.4-rev12 | |
Open-Xchange App Suite Backend | =7.10.4-rev13 | |
Open-Xchange App Suite Backend | =7.10.4-rev14 | |
Open-Xchange App Suite Backend | =7.10.4-rev15 | |
Open-Xchange App Suite Backend | =7.10.4-rev16 | |
Open-Xchange App Suite Backend | =7.10.4-rev17 | |
Open-Xchange App Suite Backend | =7.10.4-rev2 | |
Open-Xchange App Suite Backend | =7.10.4-rev3 | |
Open-Xchange App Suite Backend | =7.10.4-rev4 | |
Open-Xchange App Suite Backend | =7.10.4-rev5 | |
Open-Xchange App Suite Backend | =7.10.4-rev6 | |
Open-Xchange App Suite Backend | =7.10.4-rev7 | |
Open-Xchange App Suite Backend | =7.10.4-rev8 | |
Open-Xchange App Suite Backend | =7.10.4-rev9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37403 is rated as a medium severity vulnerability due to potential exploitation through cross-site scripting (XSS).
To fix CVE-2021-37403, upgrade to Open-Xchange App Suite version 7.10.4-rev18 or later.
CVE-2021-37403 allows attackers to perform XSS attacks through user-generated content via sharing links.
CVE-2021-37403 affects Open-Xchange App Suite versions prior to 7.10.4-rev18 and all 7.10.3 versions.
There is no officially recommended workaround for CVE-2021-37403; patching is the only solution.