CVE-2021-38374: XSS
Published Nov 22, 2021
·Updated
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.5
Event History
Nov 22, 2021
CVE Published
via MITRE·08:38 AM
Data Sourced
via MITRE·08:38 AM
Description
Frequently Asked Questions
1
What is CVE-2021-38374?
CVE-2021-38374 is a vulnerability in OX App Suite through 7.10.5 that allows XSS (Cross-Site Scripting) attacks.
2
How does CVE-2021-38374 work?
CVE-2021-38374 can be exploited by using a specially crafted snippet that contains an app loader reference within an app loader URL, leading to XSS attacks.
3
What is the severity of CVE-2021-38374?
CVE-2021-38374 has a severity rating of medium with a CVSS (Common Vulnerability Scoring System) score of 5.4.
4
Which software versions are affected by CVE-2021-38374?
OX App Suite versions up to and including 7.10.5 are affected by CVE-2021-38374.
5
Are there any known fixes for CVE-2021-38374?
Currently, there are no known fixes or patches available for CVE-2021-38374. It is recommended to update to a version of OX App Suite that is not affected.