Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14 allows remote attackers to inject arbitrary web script or HTML via an attached SVG file.
| Software | From | Fixed in |
|---|---|---|
| open-xchange / open-xchange_appsuite | 7.2.2 | 7.2.2.x |
| open-xchange / open-xchange_appsuite | 7.4.0 | 7.4.0.x |
| open-xchange / open-xchange_appsuite | 7.2.0 | 7.2.0.x |
| open-xchange / open-xchange_appsuite | 7.2.1 | 7.2.1.x |