Back to search
CVE-2016-6854
Published: Dec 15, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
92920
vdb-entry
x_refsource_BID
40377
exploit
x_refsource_EXPLOIT-DB
20160913 Open-Xchange Security Advisory 2016-09-13 (2)
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now