2024-01-09 19:00:29 +00:00

71 lines
2.7 KiB
JSON

{
"id": "CVE-2023-41710",
"sourceIdentifier": "security@open-xchange.com",
"published": "2024-01-08T09:15:20.883",
"lastModified": "2024-01-09T18:15:46.650",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.\n\n"
},
{
"lang": "es",
"value": "Se podr\u00eda almacenar un c\u00f3digo de secuencia de comandos definido por el usuario para una URL de la tienda relacionada con ventas adicionales. Este c\u00f3digo no se sanitiz\u00f3 correctamente al agregarlo al DOM. Los atacantes podr\u00edan atraer a las v\u00edctimas a cuentas de usuario con c\u00f3digo de script malicioso y obligarlas a ejecutarlo en el contexto de un dominio confiable. Agregamos sanitizaci\u00f3n para este contenido. No se conocen exploits disponibles p\u00fablicamente."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@open-xchange.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "security@open-xchange.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.com/files/176422/OX-App-Suite-7.10.6-Access-Control-Cross-Site-Scripting.html",
"source": "security@open-xchange.com"
},
{
"url": "http://seclists.org/fulldisclosure/2024/Jan/4",
"source": "security@open-xchange.com"
},
{
"url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0006.json",
"source": "security@open-xchange.com"
},
{
"url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf",
"source": "security@open-xchange.com"
}
]
}