Skip to content

CVE-2014-5234

Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via a folder publication name.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0029 (0.3%)
Percentile: 52.7%
EPSS: 2026-05-06

Affects

open-xchange:open-xchange_appsuite

Technical description

Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via a folder publication name.

Published: 9/17/2014, 2:55:03 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam