Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kattsson

#19024of 53,624
14.1Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2020-13181
4.3
2020-08-31
Open Xchange · Ox App Suite · CVE-2020-12643
**Name of the Vulnerable Software and Affected Versions** OX App Suite versions 7.10.3 and earlier **Description** The issue is related to Incorrect Access Control. It can be exploited via an "/api/subscriptions" request for a snippet containing an email address. **Recommendations** For OX App Suite versions 7.10.3 and earlier, update to a version later than 7.10.3 to resolve the issue. As a temporary workaround, consider restricting access to the "/api/subscriptions" endpoint until a patch is available.
PT-2020-13183
9.8
2020-08-31
Open Xchange · Ox App Suite · CVE-2020-12645
**Name of the Vulnerable Software and Affected Versions** OX App Suite versions 7.10.1 through 7.10.3 **Description** The issue is related to improper input validation for rate limits, which can be exploited with a crafted User-Agent header. Additionally, it involves spoofed vacation notices and excessive memory consumption through the /apps/load endpoint. **Recommendations** For OX App Suite versions 7.10.1 through 7.10.3, consider updating to a version that addresses the improper input validation issue. As a temporary workaround, restrict access to the /apps/load endpoint to minimize the risk of excessive memory consumption. Avoid using spoofed vacation notices until the issue is resolved.