CVE-2014-5236

HIGH

Open-Xchange AppSuite < 7.4.2-rev10 and 7.6.x < 7.6.0-rev10 - Path Traversal via OpenDocument File

Title source: llm
STIX 2.1

Description

Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0667
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (3)
open-xchange/open-xchange_appsuite 7.4.2 (11 CPE variants)
open-xchange/open-xchange_appsuite 7.6.0 (9 CPE variants)
open-xchange/open-xchange_appsuite < 7.4.1
Published Jan 31, 2020
Tracked Since Feb 18, 2026