Vendor: Open-Xchange GmbH Product: Open-Xchange Server 6 / OX AppSuite Internal reference: 39485 (Bug ID) Vulnerability type: Cross-Site Scripting (CWE-80) Vulnerable version: OX6 6.22.9, AppSuite 7.6.2 and earlier Vulnerable component: frontend Report confidence: Confirmed Solution status: Fixed by Vendor Fixed version: 6.22.8-rev8, 6.22.9-rev15m, 7.6.1-rev25, 7.6.2-rev20 Vendor notification: 2015-07-07 Solution date: 2015-07-24 CVE reference: CVE-2015-5375 CVSSv2: 5.7 (AV:N/AC:M/Au:N/C:P/I:N/A:N/E:POC/RL:U/RC:C/CDP:LM/TD:H/CR:ND/IR:ND/AR:ND) Vulnerability Details: Dialogs for printing content were vulnerable to execute injected script code at object properties that get printed. Risk: Malicious script code can be executed within a users context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). Potential attack vectors are E-Mail (via attachments) or Drive. Solution: Providers should update to the latest Patch Releases 6.22.8-rev8, 6.22.9-rev15m, 7.6.1-rev25, 7.6.2-rev20 (or later).