First published: Wed Aug 02 2023(Updated: )
The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.
Credit: security@open-xchange.com security@open-xchange.com
Affected Software | Affected Version | How to fix |
---|---|---|
<8.11 | ||
Open-xchange Open-xchange Appsuite Office | <8.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26440 is a vulnerability in the cacheservice API of Open-xchange Appsuite Office that could be exploited to perform arbitrary SQL queries.
CVE-2023-26440 has a severity score of 7.8, which is considered high.
Open-xchange Appsuite Office version up to and exclusive of 8.11 is affected by CVE-2023-26440.
To fix CVE-2023-26440, update to Open-xchange Appsuite Office version 8.11 or later.
More information about CVE-2023-26440 can be found in the following references: [link1], [link2], [link3].