CVE-2020-15003

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/10/2020
Last modified:
21/07/2021

Description

OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.2:*:*:*:*:*:*:*
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.3:*:*:*:*:*:*:*