CVE-2014-5238
HIGHOpen-Xchange AppSuite < 7.4.2-rev11 and 7.6.x < 7.6.0-rev9 - XXE via OpenDocument Text Document
Title source: llmDescription
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/128257/Open-Xchange-7.6.0-XSS-SSRF-Traversal.html
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/archive/1/archive/1/533443/100/0/threaded
Release Notes, Vendor Advisory x_refsource_misc
http://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_2112_7.6.0_2014-08-25.pdf
Scores
CVSS v3
7.8
EPSS
0.0050
EPSS Percentile
66.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (3)
open-xchange/open-xchange_appsuite
7.4.2 (11 CPE variants)
open-xchange/open-xchange_appsuite
7.6.0 (9 CPE variants)
open-xchange/open-xchange_appsuite
< 7.4.1
Published
Jan 14, 2020
Tracked Since
Feb 18, 2026