VulnerabilityModified
CVE-2023-26429
This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure.
MEDIUM 5.3EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are known.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- open-xchange/open-xchange appsuite backend
- Source
- security@open-xchange.com
References
- http://packetstormsecurity.com/files/173083/OX-App-Suite-SSRF-Resource-Consumption-Command-Injection.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2023/Jun/8Mailing List, Third Party Advisory
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6219_7.10.6_2023-03-20.pdfRelease Notes
- http://packetstormsecurity.com/files/173083/OX-App-Suite-SSRF-Resource-Consumption-Command-Injection.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2023/Jun/8Mailing List, Third Party Advisory
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6219_7.10.6_2023-03-20.pdfRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.