CVE-2023-41703

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
OXCNA
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
open-xchangeopen-xchange_appsuite
𝑥
< 7.10.6
open-xchangeopen-xchange_appsuite
7.10.6 <
𝑥
< 8.20
open-xchangeopen-xchange_appsuite
7.10.6
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6069
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6073
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6080
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6085
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6093
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6102
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6112
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6121
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6133
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6138
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6141
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6146
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6147
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6148
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6150
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6156
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6161
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6166
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6173
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6176
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6178
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6189
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6194
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6199
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6204
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6205
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6209
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6210
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6214
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6215
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6216
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6218
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6219
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6220
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6227
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6230
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6233
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6235
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6236
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6239
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6241
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6243
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6245
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6248
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6249
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6250
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6251
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6255
𝑥
= Vulnerable software versions