Open-Xchange AppSuite Subject Field Cross Site Scripting Vulnerability
BID:66273
Info
Open-Xchange AppSuite Subject Field Cross Site Scripting Vulnerability
| Bugtraq ID: | 66273 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2077 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2014 12:00AM |
| Updated: | Mar 17 2014 12:00AM |
| Credit: | Martin Braun |
| Vulnerable: |
Open-Xchange Open-Xchange AppSuite 7.4.2 Open-Xchange Open-Xchange AppSuite 7.4.1 |
| Not Vulnerable: |
Open-Xchange Open-Xchange AppSuite 7.4.2-rev8 Open-Xchange Open-Xchange AppSuite 7.4.1-rev10 |
Discussion
Open-Xchange AppSuite Subject Field Cross Site Scripting Vulnerability
Open-Xchange AppSuite is prone to a cross-site scripting vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected application. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Open-Xchange AppSuite 7.4.1 and 7.4.2 are vulnerable; other versions may also be affected.
Open-Xchange AppSuite is prone to a cross-site scripting vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected application. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Open-Xchange AppSuite 7.4.1 and 7.4.2 are vulnerable; other versions may also be affected.
Exploit / POC
Open-Xchange AppSuite Subject Field Cross Site Scripting Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Open-Xchange AppSuite Subject Field Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.