PT-2015-6877 · Open Xchange · Ox App Suite+1

Publicado

2015-09-28

·

Atualizado

2018-10-09

·

CVE-2015-5375

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Open-Xchange Server versions prior to 6.22.8-rev8 Open-Xchange Server versions 6.22.9 prior to 6.22.9-rev15m OX App Suite versions 7.x prior to 7.6.1-rev25 OX App Suite versions 7.6.2 prior to 7.6.2-rev20
Description A cross-site scripting (XSS) issue exists in the Front End of Open-Xchange Server and OX App Suite, allowing remote attackers to inject arbitrary web script or HTML via unknown vectors related to object properties in unspecified dialogs for printing content.
Recommendations For Open-Xchange Server versions prior to 6.22.8-rev8, update to version 6.22.8-rev8 or later. For Open-Xchange Server versions 6.22.9 prior to 6.22.9-rev15m, update to version 6.22.9-rev15m or later. For OX App Suite versions 7.x prior to 7.6.1-rev25, update to version 7.6.1-rev25 or later. For OX App Suite versions 7.6.2 prior to 7.6.2-rev20, update to version 7.6.2-rev20 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-5375

Produtos afetados

Ox App Suite
Open-Xchange Server