PT-2024-12967 · Open Xchange Gmbh+2 · Ox App Suite+1

Published

2024-01-08

·

Updated

2024-01-22

·

CVE-2023-41710

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue involves user-defined script code that could be stored for a upsell related shop URL. This code was not correctly sanitized when added to the DOM, allowing attackers to lure victims to user accounts with malicious script code and execute it in the context of a trusted domain. The problem has been addressed by adding sanitization for this content. There are no known publicly available exploits.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-41710

Affected Products

Ox App Suite
Appsuite-Frontend