Required CVE Record Information
Description
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://open-xchange.com x_transferred
- https://seclists.org/fulldisclosure/2022/Nov/18 x_transferred