CVE-2023-29047
MEDIUMOpen-Xchange AppSuite < 7.10.6 - SQL Injection via Imageconverter API
Title source: llmDescription
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content which is accessible to the imageconverter SQL user account. None No publicly available exploits are known.
References (2)
Core 2
Core References
Release Notes, Vendor Advisory release-notes
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf
Vendor Advisory vendor-advisory
https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json
Scores
CVSS v3
5.3
EPSS
0.0005
EPSS Percentile
15.6%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (2)
open-xchange/open-xchange_appsuite
7.10.6 (42 CPE variants)
open-xchange/open-xchange_appsuite
< 7.10.6
Published
Nov 02, 2023
Tracked Since
Feb 18, 2026