PT-2021-21636 · Open Xchange · Ox App Suite
Published
2021-07-22
·
Updated
2022-02-10
·
CVE-2021-37402
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OX App Suite versions prior to 7.10.3-rev32
OX App Suite version 7.10.4 prior to 7.10.4-rev18
Description
The issue allows for XSS via binary data that is mishandled when the legacy data retrieval endpoint has been enabled.
Recommendations
For OX App Suite versions prior to 7.10.3-rev32, update to version 7.10.3-rev32 or later.
For OX App Suite version 7.10.4 prior to 7.10.4-rev18, update to version 7.10.4-rev18 or later.
As a temporary workaround, consider disabling the legacy data retrieval endpoint until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ox App Suite