ZeroHour

CVE-2023-26428

CVSS 3.1
6.5 medium
EPSS
<1%p60
Published
()
Modified
Description

Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not explicitly shared with other users. No publicly available exploits are known.

Vendors
open-xchange
Products
open-xchange appsuite backend
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.