CVE-2023-26429
LOWOpen-Xchange AppSuite Backend - Control Character Injection via User Feedback
Title source: llmDescription
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are known.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/173083/OX-App-Suite-SSRF-Resource-Consumption-Command-Injection.html
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2023/Jun/8
Release Notes release-notes
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6219_7.10.6_2023-03-20.pdf
Vendor Advisory vendor-advisory
https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json
Scores
CVSS v3
3.5
EPSS
0.0017
EPSS Percentile
38.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Details
CWE
CWE-77
Status
published
Products (2)
open-xchange/open-xchange_appsuite_backend
7.10.6 (2 CPE variants)
open-xchange/open-xchange_appsuite_backend
< 7.10.6
Published
Jun 20, 2023
Tracked Since
Feb 18, 2026