Open-xchange Open-xchange Appsuite Backend 8.11.0

CPE Details

Open-xchange Open-xchange Appsuite Backend 8.11.0
8.11.0
2023-07-03
12h20 +00:00
2023-07-14
09h31 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:open-xchange:open-xchange_appsuite_backend:8.11.0:*:*:*:*:*:*:*

Informations

Vendor

open-xchange

Product

open-xchange_appsuite_backend

Version

8.11.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-26451 2023-08-02 12h23 +00:00 Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result, other users accounts could be compromised. The oAuth Authorization Service is not enabled by default. We have updated the implementation to use sources with sufficient randomness to generate authorization tokens. No publicly available exploits are known.
7.5
Haute
CVE-2023-26443 2023-08-02 12h23 +00:00 Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.
9.8
Critique