{"id":56215,"date":"2024-04-11T19:20:04","date_gmt":"2024-04-11T15:20:04","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178021\/OXAS-ADV-2024-0001.txt"},"modified":"2024-04-11T19:20:04","modified_gmt":"2024-04-11T15:20:04","slug":"ox-app-suite-7-10-6-cross-site-scripting-deserialization-issue","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/ox-app-suite-7-10-6-cross-site-scripting-deserialization-issue\/","title":{"rendered":"OX App Suite 7.10.6 Cross Site Scripting \/ Deserialization Issue"},"content":{"rendered":"<p>Dear subscribers,<\/p>\n<p>We&#8217;re sharing our latest advisory with you and like to thank everyone who contributed in finding and solving those vulnerabilities. Feel free to join our bug bounty programs for OX App Suite, Dovecot and PowerDNS at YesWeHack.<\/p>\n<p>This advisory has also been published at https:\/\/documentation.open-xchange.com\/appsuite\/security\/advisories\/html\/2024\/oxas-adv-2024-0001.html.<\/p>\n<p>Yours sincerely,<br \/>Martin Heiland, Open-Xchange GmbH<\/p>\n<p>Internal reference: OXUIB-2660<br \/>Type: CWE-79 (Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;))<br \/>Component: frontend<br \/>Report confidence: Confirmed<br \/>Solution status: Fixed by vendor<br \/>Last affected revision: OX App Suite frontend 7.10.6-rev40, OX App Suite frontend 8.20<br \/>First fixed revision: OX App Suite frontend 7.10.6-rev41, OX App Suite frontend 8.21<br \/>Discovery date: 2023-12-13<br \/>Solution date: 2024-02-05<br \/>Disclosure date: 2024-02-08<br \/>CVE: CVE-2024-23192<br \/>CVSS: 6.1 (CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N)<\/p>\n<p>Details:<br \/>XSS for RSS content using data-attributes. RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or successfully luring users to compromised accounts.<\/p>\n<p>Risk:<br \/>Attackers could perform malicious API requests or extract information from the users account. No publicly available exploits are known.<\/p>\n<p>Solution:<br \/>Please deploy the provided updates and patch releases. Potentially malicious attributes now get removed from external RSS content.<\/p>\n<p>&#8212;<\/p>\n<p>Internal reference: OXUIB-2663<br \/>Type: CWE-79 (Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;))<br \/>Component: frontend<br \/>Report confidence: Confirmed<br \/>Solution status: Fixed by vendor<br \/>Last affected revision: OX App Suite frontend 7.10.6-rev40<br \/>First fixed revision: OX App Suite frontend 7.10.6-rev41<br \/>Discovery date: 2023-12-13<br \/>Solution date: 2024-02-02<br \/>Disclosure date: 2024-02-08<br \/>CVE: CVE-2024-23191<br \/>CVSS: 5.4 (CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N)<\/p>\n<p>Details:<br \/>XSS using data- attributes at upsell ads. Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously configured accounts.<\/p>\n<p>Risk:<br \/>Attackers could perform malicious API requests or extract information from the users account. No publicly available exploits are known.<\/p>\n<p>Solution:<br \/>Please deploy the provided updates and patch releases. Sanitization of user-defined upsell content has been improved.<\/p>\n<p>&#8212;<\/p>\n<p>Internal reference: OXUIB-2688<br \/>Type: CWE-79 (Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;))<br \/>Component: frontend<br \/>Report confidence: Confirmed<br \/>Solution status: Fixed by vendor<br \/>Last affected revision: OX App Suite frontend 7.10.6-rev40<br \/>First fixed revision: OX App Suite frontend 7.10.6-rev41<br \/>Discovery date: 2024-01-09<br \/>Solution date: 2024-02-02<br \/>Disclosure date: 2024-02-08<br \/>CVE: CVE-2024-23190<br \/>CVSS: 5.4 (CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N)<\/p>\n<p>Details:<br \/>XSS using &#8220;data&#8221; attributes at upsell shop. Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously configured accounts.<\/p>\n<p>Risk:<br \/>Attackers could perform malicious API requests or extract information from the users account. No publicly available exploits are known.<\/p>\n<p>Solution:<br \/>Please deploy the provided updates and patch releases. Sanitization of user-defined upsell content has been improved.<\/p>\n<p>&#8212;<\/p>\n<p>Internal reference: OXUIB-2689<br \/>Type: CWE-79 (Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;))<br \/>Component: frontend<br \/>Report confidence: Confirmed<br \/>Solution status: Fixed by vendor<br \/>Last affected revision: OX App Suite frontend 7.10.6-rev40, OX App Suite frontend 8.21<br \/>First fixed revision: OX App Suite frontend 7.10.6-rev41, OX App Suite frontend 8.22<br \/>Discovery date: 2024-01-09<br \/>Solution date: 2024-02-01<br \/>Disclosure date: 2024-02-08<br \/>CVE: CVE-2024-23189<br \/>CVSS: 5.4 (CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:L\/A:N)<\/p>\n<p>Details:<br \/>XSS using tasks &#8220;original mail&#8221; references. Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to the users account, access to another account within the same context or an successful social engineering attack to make users import external content.<\/p>\n<p>Risk:<br \/>Attackers could perform malicious API requests or extract information from the users account. No publicly available exploits are known.<\/p>\n<p>Solution:<br \/>Please deploy the provided updates and patch releases. Sanitization of user-generated content has been improved.<\/p>\n<p>&#8212;<\/p>\n<p>Internal reference: DOCS-5222<br \/>Type: CWE-502 (Deserialization of Untrusted Data)<br \/>Component: office<br \/>Report confidence: Confirmed<br \/>Solution status: Fixed by vendor<br \/>Last affected revision: OX App Suite office 7.10.6-rev11<br \/>First fixed revision: OX App Suite office 7.10.6-rev12<br \/>Discovery date: 2024-01-24<br \/>Solution date: 2024-02-06<br \/>Disclosure date: 2024-02-08<br \/>CVE: CVE-2023-46604<br \/>CVSS: 10.0 (CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:H\/A:H)<\/p>\n<p>Details:<br \/>CVE-2023-46604 regarding office\/dcs. CVE-2023-46604 has been identified at the Apache ActiveMQ (AMQ) project which affects a version of that component shipped by OX App Suite components.<\/p>\n<p>Risk:<br \/>The vulnerability in AMQ can potentially be exploited in OX App Suite deployments, depending on network topology and configuration. No publicly available exploits are known.<\/p>\n<p>Solution:<br \/>Please deploy the provided updates and patch releases. We provide an updated version of the affected component that is not vulnerable.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dear subscribers, We&#8217;re sharing our latest advisory with you and like to thank everyone who contributed in finding and solving those vulnerabilities. Feel free to join our bug bounty programs for OX App Suite, Dovecot and PowerDNS at YesWeHack. This advisory has also been published at https:\/\/documentation.open-xchange.com\/appsuite\/security\/advisories\/html\/2024\/oxas-adv-2024-0001.html. Yours sincerely,Martin Heiland, Open-Xchange GmbH Internal reference: OXUIB-2660Type: &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56215","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56215"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56215\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}