PT-2015-6877 · Open Xchange · Ox App Suite+1

Published

2015-09-28

·

Updated

2018-10-09

·

CVE-2015-5375

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Open-Xchange Server versions prior to 6.22.8-rev8 Open-Xchange Server versions 6.22.9 prior to 6.22.9-rev15m OX App Suite versions 7.x prior to 7.6.1-rev25 OX App Suite versions 7.6.2 prior to 7.6.2-rev20
Description A cross-site scripting (XSS) issue exists in the Front End of Open-Xchange Server and OX App Suite, allowing remote attackers to inject arbitrary web script or HTML via unknown vectors related to object properties in unspecified dialogs for printing content.
Recommendations For Open-Xchange Server versions prior to 6.22.8-rev8, update to version 6.22.8-rev8 or later. For Open-Xchange Server versions 6.22.9 prior to 6.22.9-rev15m, update to version 6.22.9-rev15m or later. For OX App Suite versions 7.x prior to 7.6.1-rev25, update to version 7.6.1-rev25 or later. For OX App Suite versions 7.6.2 prior to 7.6.2-rev20, update to version 7.6.2-rev20 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5375

Affected Products

Ox App Suite
Open-Xchange Server