CVE-2023-26429
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jun 20, 2023
Updated: Jan 12, 2024
CWE ID 77
Summary
CVE-2023-26429 is a vulnerability where control characters in user feedback content were not properly removed during exportation. This issue allowed attackers to inject unexpected content, potentially disrupting the data structure. To mitigate this risk, we now eliminate all control characters except for whitespace characters during the export process. No publicly available exploits for this vulnerability have been reported.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Open-xchange Appsuite Backend