SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-41704

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine.

MEDIUM 6.1EPSS 0.53%

Does this matter?

Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.

Description

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.53% probability · 43th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
open-xchange/open-xchange appsuite
Source
security@open-xchange.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.