PT-2014-8323 · Open Xchange · Open-Xchange Appsuite

Published

2014-11-21

·

Updated

2018-10-09

·

CVE-2014-7871

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Open-Xchange (OX) AppSuite versions prior to 7.4.2-rev36 Open-Xchange (OX) AppSuite versions 7.6.x prior to 7.6.0-rev23
Description The issue allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call. This can lead to unauthorized access and manipulation of sensitive data.
Recommendations For Open-Xchange (OX) AppSuite versions prior to 7.4.2-rev36, update to version 7.4.2-rev36 or later. For Open-Xchange (OX) AppSuite versions 7.6.x prior to 7.6.0-rev23, update to version 7.6.0-rev23 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7871

Affected Products

Open-Xchange Appsuite