Open-Xchange AppSuite CVE-2014-2393 Cross Site Scripting Vulnerability
BID:66710
Info
Open-Xchange AppSuite CVE-2014-2393 Cross Site Scripting Vulnerability
| Bugtraq ID: | 66710 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2393 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2014 12:00AM |
| Updated: | Apr 08 2014 12:00AM |
| Credit: | Martin Braun |
| Vulnerable: |
Open-Xchange Open-Xchange AppSuite 7.4.2 Open-Xchange Open-Xchange AppSuite 7.4.1 |
| Not Vulnerable: |
Open-Xchange Open-Xchange AppSuite 7.4.2-rev13 Open-Xchange Open-Xchange AppSuite 7.4.1-rev11 |
Discussion
Open-Xchange AppSuite CVE-2014-2393 Cross Site Scripting Vulnerability
Open-Xchange AppSuite is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected application. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Open-Xchange AppSuite 7.4.1 and 7.4.2 are vulnerable; other versions may also be affected.
Open-Xchange AppSuite is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected application. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Open-Xchange AppSuite 7.4.1 and 7.4.2 are vulnerable; other versions may also be affected.
Exploit / POC
Open-Xchange AppSuite CVE-2014-2393 Cross Site Scripting Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Open-Xchange AppSuite CVE-2014-2393 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Open-Xchange AppSuite CVE-2014-2393 Cross Site Scripting Vulnerability
References:
References:
- Open-Xchange Homepage (Open-Xchange AG)
- Release Notes for Patch Release #1920 (Open-Xchange GmbH)
- Release Notes for Patch Release #1930 (Open-Xchange GmbH)