CVE Feed

    Dashboard / CVE / CVE-2023-29051

    CVE-2023-29051

    User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.

    Published:Jan 8, 2024
    Last Modified:Nov 4, 2025
    EPS:Jan 8, 2024
    EPSS Score:0.00129
    CVSS Score:8.1

    Affected Products

    Vendor
    Open-xchange
    Product
    Ox App Suite

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High