CVE-2013-6997
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents…
Does this matter?
Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents containing "crafted hyperlinks with script URL handlers."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- open-xchange/open-xchange appsuite
- Source
- cve@mitre.org
References
- http://software.open-xchange.com/OX6/doc/Release_Notes_for_Public_Patch_Release_1766_7.4.0_Rev21_2013_12_13.pdfVendor Advisory
- http://www.osvdb.org/101714
- http://www.osvdb.org/101715
- http://www.securityfocus.com/archive/1/530681/100/0/threaded
- http://www.securityfocus.com/bid/64676
- http://www.securitytracker.com/id/1029554
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90113
- http://software.open-xchange.com/OX6/doc/Release_Notes_for_Public_Patch_Release_1766_7.4.0_Rev21_2013_12_13.pdfVendor Advisory
- http://www.osvdb.org/101714
- http://www.osvdb.org/101715
- http://www.securityfocus.com/archive/1/530681/100/0/threaded
- http://www.securityfocus.com/bid/64676
- http://www.securitytracker.com/id/1029554
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90113
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.