CVE-2023-29043

MEDIUM

Open-Xchange AppSuite - Cross-Site Scripting via Image References

Title source: llm
STIX 2.1

Description

Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when performing certain actions, like copying content. The relevant attribute does now get encoded to avoid the possibility of executing script code. No publicly available exploits are known.

Scores

CVSS v3 6.1
EPSS 0.0012
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
open-xchange/open-xchange_appsuite 7.10.6 (42 CPE variants)
open-xchange/open-xchange_appsuite < 7.10.6
Published Nov 02, 2023
Tracked Since Feb 18, 2026