CVE-2023-26429: Command Injection
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26429?
CVE-2023-26429 is a vulnerability in Open-xchange AppSuite Backend that allowed attackers to include unexpected content via user feedback and potentially break the exported data structure.
What is the severity of CVE-2023-26429?
CVE-2023-26429 has a severity rating of medium with a severity value of 5.3.
How does CVE-2023-26429 affect Open-xchange AppSuite Backend?
CVE-2023-26429 affects Open-xchange AppSuite Backend versions up to and including 7.10.6 and versions between 8.0.0 and 8.11.0.
How can CVE-2023-26429 be fixed?
To fix CVE-2023-26429, update Open-xchange AppSuite Backend to a version that is not affected by the vulnerability.
Are there any references related to CVE-2023-26429?
Yes, you can find references related to CVE-2023-26429 at the following links: [http://packetstormsecurity.com/files/173083/OX-App-Suite-SSRF-Resource-Consumption-Command-Injection.html](http://packetstormsecurity.com/files/173083/OX-App-Suite-SSRF-Resource-Consumption-Command-Injection.html), [http://seclists.org/fulldisclosure/2023/Jun/8](http://seclists.org/fulldisclosure/2023/Jun/8), [https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json](https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json).