CVE-2021-38375: XSS
Published Nov 22, 2021
·Updated
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.5
Event History
Nov 22, 2021
CVE Published
via MITRE·08:40 AM
Data Sourced
via MITRE·08:40 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38375.
2
What is the severity of CVE-2021-38375?
CVE-2021-38375 has a severity rating of medium.
3
How does the vulnerability in OX App Suite through 7.10.5 allow XSS?
This vulnerability allows cross-site scripting (XSS) attacks by exploiting the alt attribute of an IMG element in a truncated e-mail message.
4
Which versions of OX App Suite are affected by CVE-2021-38375?
OX App Suite versions up to and including 7.10.5 are affected by CVE-2021-38375.
5
Is there any fix available for CVE-2021-38375?
To mitigate the vulnerability, it is recommended to update OX App Suite to a version that has addressed the issue.