PT-2021-22091 · Open Xchange · Ox App Suite

Published

2021-11-22

·

Updated

2022-07-12

·

CVE-2021-38377

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OX App Suite versions 7.10.5 and earlier
Description The issue allows for XSS via JavaScript code in an anchor HTML comment within truncated e-mail. This is possible because there is a predictable UUID with HTML transformation results.
Recommendations For OX App Suite versions 7.10.5 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38377

Affected Products

Ox App Suite