CVE-2023-41710 MEDIUM

CVE-2023-41710

Vendor Open-Xchange Gmbh
Product OX App Suite
Weakness CWE-79 · XSS
Published January 8, 2024
Last update November 4, 2025

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

Key dates

02Disclosure timeline

January 8, 2024 CVE published
November 4, 2025 Record updated

Related vulnerabilities

04Related CVE