CVE-2023-41704

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
OXCNA
7.1 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
open-xchangeopen-xchange_appsuite
𝑥
< 7.6.3
open-xchangeopen-xchange_appsuite
7.6.3 <
𝑥
< 7.10.6
open-xchangeopen-xchange_appsuite
7.10.6 <
𝑥
< 8.20
open-xchangeopen-xchange_appsuite
7.6.3
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3464
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3519
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3569
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3627
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3728
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3875
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3922
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3949
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_3991
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4047
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4133
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4423
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4470
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4552
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4667
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4750
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4789
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4839
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4860
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_4895
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_5104
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_5165
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_5231
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_5537
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_5637
open-xchangeopen-xchange_appsuite
7.6.3:patch_release_5910
open-xchangeopen-xchange_appsuite
7.10.6
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6069
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6073
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6080
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6085
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6093
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6102
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6112
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6121
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6133
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6138
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6141
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6146
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6147
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6148
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6150
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6156
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6161
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6166
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6173
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6176
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6178
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6189
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6194
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6199
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6204
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6205
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6209
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6210
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6214
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6215
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6216
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6218
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6219
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6220
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6227
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6230
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6233
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6235
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6236
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6239
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6241
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6243
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6245
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6248
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6249
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6250
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6251
open-xchangeopen-xchange_appsuite
7.10.6:patch_release_6255
𝑥
= Vulnerable software versions