CVE-2017-6913
MEDIUMOpen-Xchange AppSuite < 7.6.3 - Cross-Site Scripting via Time Tag Event Attribute
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-6913. PoCs published by gquere.
AI-analyzed exploit summary This repository documents a stored XSS vulnerability in Open-Xchange OX App Suite's webmail, where event attributes of the HTML time tag were not properly filtered, allowing JavaScript execution. The vulnerability was patched in version 7.6.3-rev28.
Description
Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.
Exploits (1)
This repository documents a stored XSS vulnerability in Open-Xchange OX App Suite's webmail, where event attributes of the HTML time tag were not properly filtered, allowing JavaScript execution. The vulnerability was patched in version 7.6.3-rev28.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N