CVE-2023-26448: XSS
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize jslob content for those locations to avoid redirects to malicious content. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26448?
CVE-2023-26448 is a vulnerability in Open-xchange Appsuite Frontend that allows malicious script code to be executed within the victim's context, leading to session hijacking or triggering unwanted actions via the web interface and API.
How severe is CVE-2023-26448?
CVE-2023-26448 has a severity rating of 5.4, which is classified as medium.
Which software versions are affected by CVE-2023-26448?
Open-xchange Appsuite Frontend versions up to and including 7.10.6 are affected by CVE-2023-26448.
How can CVE-2023-26448 be exploited?
CVE-2023-26448 can be exploited by using custom log-in and log-out locations with malicious protocol handlers to execute script code within the victim's context.
Is there a fix available for CVE-2023-26448?
Yes, a patch release (6230_7.10.6) is available to address the vulnerability in Open-xchange Appsuite Frontend.