Release date:
Updated on:
Affected Systems:
Open-xchange Open-Xchange Server 7.4.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65013
CVE (CAN) ID: CVE-2013-7143
Open-Xchange Server is a part of Open-source projects that mainly develop collaborative software, such as email and calendar.
If the embedded JS Code of Open-Xchange AppSuite 7.4.1 and earlier versions contain the title of the email filter rule, you can execute the embedded code.
<* Source: Open-Xchange
Link: http://www.securityfocus.com/archive/1/530804
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
Avoid opening suspicious email attachments or files.
Vendor patch:
Open-xchange
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.open-xchange.com/home.html