Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Open\-Xchange_appsuite
(Open\-Xchange)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 157 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-06-16 | CVE-2020-8543 | OX App Suite through 7.10.3 has Improper Input Validation. | Open\-Xchange_appsuite | 7.5 | ||
2020-06-16 | CVE-2020-8542 | OX App Suite through 7.10.3 allows XSS. | Open\-Xchange_appsuite | 5.4 | ||
2020-06-16 | CVE-2020-8544 | OX App Suite through 7.10.3 allows SSRF. | Open\-Xchange_appsuite | 6.5 | ||
2020-06-16 | CVE-2020-8541 | OX App Suite through 7.10.3 allows XXE attacks. | Open\-Xchange_appsuite | 6.5 | ||
2020-10-23 | CVE-2020-15002 | OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. | Open\-Xchange_appsuite | 5.0 | ||
2020-10-23 | CVE-2020-15003 | OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access). | Open\-Xchange_appsuite | 4.3 | ||
2020-10-23 | CVE-2020-15004 | OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS. | Open\-Xchange_appsuite | 4.8 | ||
2021-01-12 | CVE-2020-24700 | OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring. | Open\-Xchange_appsuite | 5.4 | ||
2021-01-12 | CVE-2020-24701 | OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI). | Open\-Xchange_appsuite | 6.1 | ||
2021-01-12 | CVE-2021-23927 | OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request. | Open\-Xchange_appsuite | 6.4 |