CVE-2014-2393
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0022 (0.2%)
Percentile: 45.1%
EPSS: 2026-05-06
Affects
open-xchange:open-xchange_appsuiteTechnical description
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.
Published: 4/24/2014, 5:06:05 AM
Last modified: 5/6/2026, 10:30:45 PM