CVE-2013-2583
Last modified
CVE-2013-2583 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev16, 6.22.0 before rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL, (2) malformed nested SCRIPT elements, (3) a mail signature, or (4) JavaScript code within an image file.. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev16, 6.22.0 before rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL, (2) malformed nested SCRIPT elements, (3) a mail signature, or (4) JavaScript code within an image file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Open-Xchange | Open-Xchange Appsuite | 6.20.7 |
| Open-Xchange | Open-Xchange Appsuite | 6.22.0 |
| Open-Xchange | Open-Xchange Appsuite | 6.22.1 |
| Open-Xchange | Open-Xchange Appsuite | 7.0.1 |
| Open-Xchange | Open-Xchange Appsuite | 7.0.2 |
| Open-Xchange | Open-Xchange Server | 6.20.7 |
| Open-Xchange | Open-Xchange Server | 6.22.0 |
| Open-Xchange | Open-Xchange Server | 6.22.1 |
| Open-Xchange | Open-Xchange Server | 7.0.1 |
| Open-Xchange | Open-Xchange Server | 7.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2583?
How severe is CVE-2013-2583?
How do I fix CVE-2013-2583?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-2577Buffer overflow in XnView before 2.04 allows remote attacker…
- CVE-2013-2578cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-…
- CVE-2013-2579TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC31…
- CVE-2013-2580Unrestricted file upload vulnerability in cgi-bin/uploadfile…
- CVE-2013-2581cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-…
- CVE-2013-2582CRLF injection vulnerability in the redirect servlet in Open…
- CVE-2013-2585Cross-site scripting (XSS) vulnerability in Atmail Webmail S…
- CVE-2013-2586XAMPP 1.8.1 does not properly restrict access to xampp/lang.…
- CVE-2013-2594SQL injection vulnerability in reports/calldiary.php in Horn…
- CVE-2013-2595The device-initialization functionality in the MSM camera dr…
- CVE-2013-2596Integer overflow in the fb_mmap function in drivers/video/fb…7.8
- CVE-2013-2597Stack-based buffer overflow in the acdb_ioctl function in au…8.4
Are you affected by CVE-2013-2583?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
