First published: Mon Nov 22 2021(Updated: )
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-xchange Ox App Suite | <=7.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38376 is a vulnerability in OX App Suite through version 7.10.5 that allows incorrect access control for retrieval of session information.
CVE-2021-38376 has a severity rating of medium with a CVSS score of 5.3.
The affected software for CVE-2021-38376 is Open-xchange Ox App Suite up to and including version 7.10.5.
To fix CVE-2021-38376, update your Open-xchange Ox App Suite software to a version that is not affected by the vulnerability.
You can find more information about CVE-2021-38376 on the following references: [http://packetstormsecurity.com/files/165038/OX-App-Suite-7.10.5-Cross-Site-Scripting-Information-Disclosure.html](http://packetstormsecurity.com/files/165038/OX-App-Suite-7.10.5-Cross-Site-Scripting-Information-Disclosure.html), [https://seclists.org/fulldisclosure/2021/Nov/43](https://seclists.org/fulldisclosure/2021/Nov/43), [https://www.open-xchange.com](https://www.open-xchange.com).