CVE-2021-44211: XSS
Published Mar 28, 2022
·Updated
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.5
Event History
Mar 28, 2022
CVE Published
via MITRE·01:01 AM
Data Sourced
via MITRE·01:01 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-44211.
2
What is the affected software?
The affected software is OX App Suite version 7.10.5.
3
What is the severity of CVE-2021-44211?
The severity of CVE-2021-44211 is medium with a CVSS score of 5.4.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by injecting malicious code into an HTML e-mail signature's class attribute.
5
Are there any known fixes for this vulnerability?
Yes, it is recommended to update to a version of OX App Suite that is not affected by this vulnerability.