CVE-2021-38377
22.11.2021, 09:15
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.Enginsight
Vendor | Product | Version |
---|---|---|
open-xchange | ox_app_suite | 𝑥 ≤ 7.10.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References