First published: Mon Feb 12 2024(Updated: )
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.
Credit: security@open-xchange.com
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | <7.10.6 | |
Open-Xchange App Suite Backend | =7.10.6 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6069 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6073 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6080 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6085 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6093 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6102 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6112 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6121 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6133 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6138 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6141 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6146 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6147 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6148 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6150 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6156 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6161 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6166 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6173 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6176 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6178 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6189 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6194 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6199 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6204 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6205 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6209 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6210 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6214 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6215 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6216 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6218 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6219 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6220 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6227 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6230 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6233 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6235 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6236 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6239 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6241 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6243 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6245 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6248 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6249 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6250 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6251 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6255 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41708 has been classified with a medium severity due to its potential for cross-site scripting attacks.
To resolve CVE-2023-41708, you should deploy the latest patch releases provided for Open-Xchange App Suite.
CVE-2023-41708 is a cross-site scripting vulnerability that can allow attackers to inject malicious script code.
CVE-2023-41708 affects Open-Xchange App Suite versions prior to 7.10.6 and all patch releases that do not address this issue.
If you cannot upgrade, you should implement additional security measures such as input validation or strict sanitization of URLs to mitigate the effects of CVE-2023-41708.