OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ox_app_suite | Open-xchange | * | 7.10.6 (excluding) |
Ox_app_suite | Open-xchange | 7.10.6 (including) | 7.10.6 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev01 (including) | 7.10.6-rev01 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev02 (including) | 7.10.6-rev02 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev03 (including) | 7.10.6-rev03 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev04 (including) | 7.10.6-rev04 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev05 (including) | 7.10.6-rev05 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev06 (including) | 7.10.6-rev06 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev07 (including) | 7.10.6-rev07 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev08 (including) | 7.10.6-rev08 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev09 (including) | 7.10.6-rev09 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev10 (including) | 7.10.6-rev10 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev11 (including) | 7.10.6-rev11 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev12 (including) | 7.10.6-rev12 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev13 (including) | 7.10.6-rev13 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev14 (including) | 7.10.6-rev14 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev15 (including) | 7.10.6-rev15 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev16 (including) | 7.10.6-rev16 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev17 (including) | 7.10.6-rev17 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev18 (including) | 7.10.6-rev18 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev19 (including) | 7.10.6-rev19 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev20 (including) | 7.10.6-rev20 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev21 (including) | 7.10.6-rev21 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev22 (including) | 7.10.6-rev22 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev23 (including) | 7.10.6-rev23 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev24 (including) | 7.10.6-rev24 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev25 (including) | 7.10.6-rev25 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev26 (including) | 7.10.6-rev26 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev27 (including) | 7.10.6-rev27 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev28 (including) | 7.10.6-rev28 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev29 (including) | 7.10.6-rev29 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev30 (including) | 7.10.6-rev30 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev31 (including) | 7.10.6-rev31 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev32 (including) | 7.10.6-rev32 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev33 (including) | 7.10.6-rev33 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev34 (including) | 7.10.6-rev34 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev35 (including) | 7.10.6-rev35 (including) |
Ox_app_suite | Open-xchange | 7.10.6-rev36 (including) | 7.10.6-rev36 (including) |