The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed w…
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker wi…
Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious …
The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within th…
The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped…
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserializa…
Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other use…
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and …
It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could disco…
OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an un…
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.
OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.
OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.
OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail sig…
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversio…
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.