CVE-2023-41704
CVSS V2 None
CVSS V3 None
Description
Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.
Overview
- CVE ID
- CVE-2023-41704
- Assigner
- OX
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-12T08:15:22.352Z
- Last Modified Date
- 2024-02-16T14:08:49.359Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf | release-notes |
https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0007.json | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-41704 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41704 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 04:01:22 | Added to TrackCVE |