PT-2023-19701 · Open Xchange · Ox App Suite
Tim Coen
·
Published
2023-05-29
·
Updated
2025-01-14
·
CVE-2023-24599
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OX App Suite versions prior to 7.10.6-rev37
Description
The issue allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, also referred to as "ID confusion."
Recommendations
For versions prior to 7.10.6-rev37, update to version 7.10.6-rev37 or later to resolve the issue. As a temporary workaround, consider restricting access to appointment modification features to minimize the risk of exploitation.
Fix
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ox App Suite