PT-2014-3072 · Open Xchange · Open-Xchange Appsuite
Published
2014-12-27
·
Updated
2014-12-29
·
CVE-2013-6241
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open-Xchange (OX) AppSuite versions 7.2.x through 7.2.2-rev24
Open-Xchange (OX) AppSuite versions 7.4.x through 7.4.0-rev13
Description
The issue concerns the Birthday widget in the backend of Open-Xchange (OX) AppSuite. In certain user-id sharing scenarios, it does not properly construct a SQL statement for next-year birthdays. This allows remote authenticated users to obtain sensitive information, including birthday, displayname, firstname, and surname, via a birthdays action to the "api/contacts" endpoint.
Recommendations
For Open-Xchange (OX) AppSuite versions 7.2.x through 7.2.2-rev24, update to version 7.2.2-rev25 or later.
For Open-Xchange (OX) AppSuite versions 7.4.x through 7.4.0-rev13, update to version 7.4.0-rev14 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Xchange Appsuite