PT-2023-20625 · Ox Software Gmbh+1 · Ox App Suite+1
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Software (affected versions not specified)
Description
The issue arises from control characters not being removed when exporting user feedback content, allowing attackers to include unexpected content and potentially break the exported data structure. This is mitigated by dropping all control characters that are not whitespace characters during the export. No publicly available exploits are known.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ox App Suite
Open-Xchange Appsuite Backend