Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving 'the aria "tags" for screenreaders at the top bar'.
References 2 Total
- secunia.com: 57290 third-party-advisory
- archives.neohapsis.com: 20140317 Open-Xchange Security Advisory 2014-03-17 mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- secunia.com: 57290 third-party-advisoryx_transferred
- archives.neohapsis.com: 20140317 Open-Xchange Security Advisory 2014-03-17 mailing-listx_transferred