VulnerabilityModified
CVE-2021-38376
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
MEDIUM 5.3EPSS 1.44%
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- open-xchange/ox app suite
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/165038/OX-App-Suite-7.10.5-Cross-Site-Scripting-Information-Disclosure.htmlExploit, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Nov/43Exploit, Mailing List, Third Party Advisory
- https://www.open-xchange.comProduct
- http://packetstormsecurity.com/files/165038/OX-App-Suite-7.10.5-Cross-Site-Scripting-Information-Disclosure.htmlExploit, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Nov/43Exploit, Mailing List, Third Party Advisory
- https://www.open-xchange.comProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.