Security Advisory

CVE-2016-6848

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2016-12-15 06:31:00
Last updated 2024-08-06 01:43:38
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a trusted domain without authentication that, if executed by the user, may lead to local code execution.