CVE-2014-5238

HIGH

Open-Xchange AppSuite < 7.4.2-rev11 and 7.6.x < 7.6.0-rev9 - XXE via OpenDocument Text Document

Title source: llm
STIX 2.1

Description

XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.

References (3)

Core 3

Scores

CVSS v3 7.8
EPSS 0.0050
EPSS Percentile 66.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (3)
open-xchange/open-xchange_appsuite 7.4.2 (11 CPE variants)
open-xchange/open-xchange_appsuite 7.6.0 (9 CPE variants)
open-xchange/open-xchange_appsuite < 7.4.1
Published Jan 14, 2020
Tracked Since Feb 18, 2026