PT-2016-6667 · Open Xchange · Open-Xchange Appsuite

Jakub A>>Oczek

·

Publicado

2016-12-15

·

Atualizado

2018-10-19

·

CVE-2016-5740

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open-Xchange OX App Suite versions prior to 7.8.2-rev5
Description An issue allows JavaScript code to be executed within a user's context when it is included in ical attachments within scheduling emails. This code can be presented to the user in the E-Mail App, depending on the invitation workflow, and can lead to malicious script execution. This can result in session hijacking or triggering unwanted actions via the web interface, such as sending mail or deleting data.
Recommendations For Open-Xchange OX App Suite versions prior to 7.8.2-rev5, update to version 7.8.2-rev5 or later to resolve the issue. As a temporary workaround, consider restricting the handling of ical attachments within scheduling emails to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-5740

Produtos afetados

Open-Xchange Appsuite