OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://open-xchange.com | product |
http://seclists.org/fulldisclosure/2023/May/3 | third party advisory mailing list |