vendor:
OX App Suite
by:
Jakub A>>oczek
6,1
CVSS
MEDIUM
Cross Site Scripting (CWE-80)
80
CWE
Product Name: OX App Suite
Affected Version From: 7.8.2 and earlier
Affected Version To: 7.6.2-rev58, 7.6.3-rev14, 7.8.0-rev36, 7.8.1-rev18, 7.8.2-rev5
Patch Exists: YES
Related CWE: CVE-2016-5740
CPE: a:ox_software_gmbh:ox_app_suite
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Cross Site Scripting in OX App Suite
The backend of OX App Suite was vulnerable to Cross Site Scripting. This vulnerability was caused by insufficient input validation of user supplied data. Malicious script code can be executed within a users context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
Mitigation:
Permission settings can be temporarily tightened to reject resource modifications by users. Such descriptions are now handled as plain-text to avoid any kind of script execution. Operators should update to the latest Patch Release.