CVE-2017-6913

MEDIUM

Open-Xchange AppSuite < 7.6.3 - Cross-Site Scripting via Time Tag Event Attribute

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-6913. PoCs published by gquere.

AI-analyzed exploit summary This repository documents a stored XSS vulnerability in Open-Xchange OX App Suite's webmail, where event attributes of the HTML time tag were not properly filtered, allowing JavaScript execution. The vulnerability was patched in version 7.6.3-rev28.

Description

Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.

Exploits (1)

nomisec WRITEUP 2 stars
by gquere · poc
https://github.com/gquere/CVE-2017-6913

This repository documents a stored XSS vulnerability in Open-Xchange OX App Suite's webmail, where event attributes of the HTML time tag were not properly filtered, allowing JavaScript execution. The vulnerability was patched in version 7.6.3-rev28.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Open-Xchange OX App Suite webmail < 7.6.3-rev28
No auth needed
Prerequisites: Victim must open a malicious email containing the crafted HTML time tag
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/gquere/CVE-2017-6913

Scores

CVSS v3 6.1
EPSS 0.0097
EPSS Percentile 57.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
open-xchange/open-xchange_appsuite < 7.6.3
Published Sep 18, 2018
Tracked Since Feb 18, 2026