CVE-2016-6842 Vulnerability Details

  /     /     /  

CVE-2016-6842 Metadata Quick Info

CVE Published: 15/12/2016 | CVE Updated: 06/08/2024 | CVE Year: 2016
Source: mitre | Vendor: n/a | Product: n/a
Status : PUBLISHED

CVE-2016-6842 Description

An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user\'s name to JS code makes that code execute when selecting that user\'s "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code can be executed within a user\'s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: n/a
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).