Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents containing "crafted hyperlinks with script URL handlers."
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/90113 | vdb entry |
http://www.securityfocus.com/bid/64676 | vdb entry |
http://software.open-xchange.com/OX6/doc/Release_Notes_for_Public_Patch_Release_1766_7.4.0_Rev21_2013_12_13.pdf | vendor advisory |
http://www.osvdb.org/101714 | vdb entry |
http://www.securitytracker.com/id/1029554 | vdb entry |
http://www.osvdb.org/101715 | vdb entry |
http://www.securityfocus.com/archive/1/530681/100/0/threaded | mailing list |