Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No publicly available exploits are known
Metrics
Affected Vendors & Products
References
History
Fri, 28 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-xchange
Open-xchange ox App Suite |
|
| Vendors & Products |
Open-xchange
Open-xchange ox App Suite |
Thu, 27 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No publicly available exploits are known | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published: 2025-11-27T09:23:07.221Z
Updated: 2025-11-28T15:18:06.927Z
Reserved: 2025-03-18T08:39:46.883Z
Link: CVE-2025-30186
Updated: 2025-11-28T15:17:59.361Z
Status : Awaiting Analysis
Published: 2025-11-27T10:15:51.420
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-30186
No data.