References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-02-12 09:15
Updated : 2024-11-21 08:21
NVD link : CVE-2023-41708
Mitre link : CVE-2023-41708
CVE.ORG link : CVE-2023-41708
JSON object : View
Products Affected
open-xchange
- open-xchange_appsuite
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')