CVE-2014-5236
HIGHOpen-Xchange AppSuite < 7.4.2-rev10 and 7.6.x < 7.6.0-rev10 - Path Traversal via OpenDocument File
Title source: llmDescription
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/128257/Open-Xchange-7.6.0-XSS-SSRF-Traversal.html
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/archive/1/archive/1/533443/100/0/threaded
Release Notes, Vendor Advisory x_refsource_misc
http://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_2112_7.6.0_2014-08-25.pdf
Scores
CVSS v3
7.5
EPSS
0.0667
EPSS Percentile
91.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (3)
open-xchange/open-xchange_appsuite
7.4.2 (11 CPE variants)
open-xchange/open-xchange_appsuite
7.6.0 (9 CPE variants)
open-xchange/open-xchange_appsuite
< 7.4.1
Published
Jan 31, 2020
Tracked Since
Feb 18, 2026