CVE-2023-24605 Information

Description

OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints e.g. reading from a drive reading contact data and renaming tokens.

Reference

https://open-xchange.com http://seclists.org/fulldisclosure/2023/May/3

Share on: