CVE-2023-41704

HIGH

Open-Xchange AppSuite < 7.6.3 - Stored Cross-Site Scripting via CID Reference Handling

Title source: llm
STIX 2.1

Description

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

Scores

CVSS v3 7.1
EPSS 0.0046
EPSS Percentile 64.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
open-xchange/open-xchange_appsuite 7.6.3 (27 CPE variants)
open-xchange/open-xchange_appsuite 7.10.6 (23 CPE variants)
Published Feb 12, 2024
Tracked Since Feb 18, 2026