CVE-2022-31468: XSS
Published Oct 24, 2022
·Updated
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=8.2
Event History
Oct 24, 2022
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
Description
Oct 25, 2022
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-31468?
The severity of CVE-2022-31468 is medium with a severity value of 6.1.
2
How does CVE-2022-31468 affect Open-xchange Ox App Suite?
CVE-2022-31468 affects Open-xchange Ox App Suite version up to and including 8.2.
3
What is the vulnerability description of CVE-2022-31468?
CVE-2022-31468 allows cross-site scripting (XSS) attacks via an attachment or OX Drive content when a client uses the len or off parameter.
4
How can CVE-2022-31468 be exploited?
CVE-2022-31468 can be exploited by injecting malicious scripts via an attachment or OX Drive content when using the len or off parameter.
5
Is there a fix available for CVE-2022-31468?
Yes, applying the latest security patches from Open-xchange is recommended to fix CVE-2022-31468.