CVE-2016-2840 Information
Description
An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The \session\ parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can be executed within a trusted domain’s context. While no OX App Suite specific data can be manipulated the vulnerability can be exploited without being authenticated and therefore used for social engineering attacks stealing cookies or redirecting from trustworthy to malicious hosts.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
http://packetstormsecurity.com/files/136543/Open-Xchange-7.8.0-Cross-Site-Scripting.html http://www.securityfocus.com/archive/1/537959/100/0/threaded http://www.securitytracker.com/id/1035469
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: