CVE-2023-26456
02.11.2023, 14:15
Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to trigger persistent code execution, allowing an attacker to build a foothold. Sanitization is in place for product names now. No publicly available exploits are known.
Vendor | Product | Version |
---|---|---|
open-xchange | ox_guard | 𝑥 < 2.10.7 |
open-xchange | ox_guard | 2.10.7 |
open-xchange | ox_guard | 2.10.7:rev4 |
open-xchange | ox_guard | 2.10.7:rev5 |
open-xchange | ox_guard | 2.10.7:rev6 |
𝑥
= Vulnerable software versions
References