CVE-2021-38377
22.11.2021, 09:15
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.Enginsight
| Vendor | Product | Version |
|---|---|---|
| open-xchange | ox_app_suite | 𝑥 ≤ 7.10.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References