CVE-2023-41703
CVSS V2 None
CVSS V3 None
Description
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.
Overview
- CVE ID
- CVE-2023-41703
- Assigner
- OX
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-12T08:15:21.605Z
- Last Modified Date
- 2024-06-04T17:21:38.083Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf | release-notes |
https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0007.json | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-41703 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41703 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 03:22:49 | Added to TrackCVE |