packetstormsecurity.com
http://packetstormsecurity.com/files/160853/OX-App-Suite-OX-Documents-7.10.x-XSS-SSRF.html CVE-2020-24701
MEDIUMNuclei
OX Appsuite - Cross-Site Scripting
Record summary
CVE-2020-24701 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMOX Appsuite - Cross-Site ScriptingCVSS 6.1
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
Impact
Attackers can inject malicious JavaScript through the PATH_INFO parameter, potentially stealing session cookies or performing unauthorized actions on behalf of users.
Remediation
Upgrade to OX App Suite version 7.10.5 or later.
WeaknessesCWE-79
AuthorsDhiyaneshDk
Template tagscvecve2020packetstormseclistsappsuitexssopen-xchangevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:*
Shodan: html:"Appsuite"
Shodan: http.html:"appsuite"
FOFA: body="appsuite"
https://packetstormsecurity.com/files/163527/OX-App-Suite-OX-Guard-OX-Documents-SSRF-Cross-Site-Scripting.html https://seclists.org/fulldisclosure/2021/Jul/33 https://nvd.nist.gov/vuln/detail/CVE-2020-24701 https://www.open-xchange.com/ https://github.com/20142995/sectool
Source: ProjectDiscovery
References
5packetstormsecurity.com
http://packetstormsecurity.com/files/163527/OX-App-Suite-OX-Guard-OX-Documents-SSRF-Cross-Site-Scripting.html 20210716 Open-Xchange Security Advisory 2021-07-15mailing list
http://seclists.org/fulldisclosure/2021/Jul/33 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24701 open-xchange.com
https://www.open-xchange.com/