CVE-2021-38377: XSS
Published Nov 22, 2021
·Updated
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.5
Event History
Nov 22, 2021
CVE Published
via MITRE·08:51 AM
Data Sourced
via MITRE·08:51 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-38377.
2
What is the title of this vulnerability?
The title of this vulnerability is 'OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail'.
3
What is the severity of CVE-2021-38377?
The severity of CVE-2021-38377 is medium with a CVSS score of 6.1.
4
Which software is affected by CVE-2021-38377?
OX App Suite version up to 7.10.5 is affected by CVE-2021-38377.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by injecting JavaScript code in an anchor HTML comment within a truncated email.