Back to Database
Status published
Medium
CVE-2018-12611
OX App Suite 7.8.4 and earlier allows Directory Traversal....
Vulnerability Description
OX App Suite 7.8.4 and earlier allows Directory Traversal.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-12611
Credits & Attribution
No credits recorded in the NVD database.
References
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_4789_7.6.3_2018-06-25.pdf
- http://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_4791_7.8.4_2018-06-25.pdf
- http://seclists.org/fulldisclosure/2019/Jan/10
- https://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_4790_7.8.3_2018-06-25.pdf
More from open-xchange
View All →CVE-2022-43699
OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account...
Unknown
0
CVE-2022-43698
OX App Suite before 7.10.6-rev30 allows SSRF because changing a...
Unknown
0
CVE-2022-43697
OX App Suite before 7.10.6-rev30 allows XSS via an activity...
Unknown
0
CVE-2022-43696
OX App Suite before 7.10.6-rev20 allows XSS via upsell ads....
Unknown
0
CVE-2022-37313
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF...
Unknown
0
Affected Vendor
open-xchange
View all reports →Affected Software
open-xchange appsuite
Vulnerable Versions:
0
Timeline
Official Publish:
January 29th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.