CVE-2023-29049 MEDIUM

CVE-2023-29049

Vendor Open-Xchange Gmbh
Product OX App Suite
Weakness CWE-79 · XSS
Published January 8, 2024
Last update April 17, 2025

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a trusted domain. User input for this widget is now sanitized to avoid malicious content the be processed. No publicly available exploits are known.

Key dates

02Disclosure timeline

January 8, 2024 CVE published
April 17, 2025 Record updated