vendor:
Open-Xchange Server 6
by:
Open-Xchange GmbH
4,5
CVSS
(AV:L/AC:H/Au:S/C:P/I:P/A:N/E:P/RL:U/RC:C/CDP:LM/TD:H/CR:ND/IR:ND/AR:ND)
Cross Site Scripting
79
CWE
Product Name: Open-Xchange Server 6
Affected Version From: 6.22.1-rev13
Affected Version To: 6.20.7-rev14, 6.22.0-rev13, 6.22.1-rev14
Patch Exists: YES
Related CWE: CVE-2013-1646
CPE: a:open-xchange:open-xchange_server_6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Multiple security issues for Open-Xchange Server
Since user input is not fully sanitized, carefully crafted content gets returned as JS code which can be used to execute arbitrary JS code at the users context.
Mitigation:
Fixed by Vendor