CVE-2016-6851
MEDIUMOpen-Xchange OX Guard < 2.4.2 - Unauthenticated Stored Cross-Site Scripting via Guest Reader Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-6851. PoCs published by Benjamin Daniel Mussler.
AI-analyzed exploit summary This is a vulnerability writeup detailing three XSS vulnerabilities in OX Guard. It describes the vulnerabilities, steps to reproduce, and solutions but does not contain exploit code.
Description
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users since no prior authentication is needed. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.) in case the user has an active session on the same domain already.
Exploits (1)
This is a vulnerability writeup detailing three XSS vulnerabilities in OX Guard. It describes the vulnerabilities, steps to reproduce, and solutions but does not contain exploit code.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N