First published: Mon Oct 24 2022(Updated: )
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-xchange Ox App Suite | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-31468 is medium with a severity value of 6.1.
CVE-2022-31468 affects Open-xchange Ox App Suite version up to and including 8.2.
CVE-2022-31468 allows cross-site scripting (XSS) attacks via an attachment or OX Drive content when a client uses the len or off parameter.
CVE-2022-31468 can be exploited by injecting malicious scripts via an attachment or OX Drive content when using the len or off parameter.
Yes, applying the latest security patches from Open-xchange is recommended to fix CVE-2022-31468.