CVE-2023-26439

The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users cached data. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open-xchange:open-xchange_appsuite_office:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:51

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2023/Aug/8 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2023/Aug/8 - Mailing List, Third Party Advisory
References () https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json - () https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json -
References () https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf - Release Notes () https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf - Release Notes
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.6

12 Jan 2024, 08:15

Type Values Removed Values Added
References
  • {'url': 'https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json', 'name': 'https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • () https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json -

08 Aug 2023, 18:24

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:open-xchange:open-xchange_appsuite_office:*:*:*:*:*:*:*:*
First Time Open-xchange
Open-xchange open-xchange Appsuite Office
References (MISC) http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html - (MISC) http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html - Third Party Advisory, VDB Entry
References (MISC) https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json - (MISC) https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json - Vendor Advisory
References (MISC) http://seclists.org/fulldisclosure/2023/Aug/8 - (MISC) http://seclists.org/fulldisclosure/2023/Aug/8 - Mailing List, Third Party Advisory
References (MISC) https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf - (MISC) https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf - Release Notes

03 Aug 2023, 16:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html -

02 Aug 2023, 20:15

Type Values Removed Values Added
References
  • (MISC) http://seclists.org/fulldisclosure/2023/Aug/8 -

02 Aug 2023, 13:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-02 13:15

Updated : 2024-11-21 07:51


NVD link : CVE-2023-26439

Mitre link : CVE-2023-26439

CVE.ORG link : CVE-2023-26439


JSON object : View

Products Affected

open-xchange

  • open-xchange_appsuite_office
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')