Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to trigger persistent code execution, allowing an attacker to build a foothold. Sanitization is in place for product names now. No publicly available exploits are known.
CVE ID: CVE-2023-26456
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.4
Vendor: OX Software GmbH
Product: OX App Suite
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 25.25% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)