CVE-2016-4047 describes an information disclosure vulnerability in Open-Xchange OX App Suite versions prior to 7.8.1-rev8. The flaw allows attackers to embed external DTD references within .docx and .xlsx files, which are then requested during document parsing. This enables tracking of document access and potential exposure of internal infrastructure details. Rated with a CVSS score of 4.3 (Medium), this vulnerability has a network attack vector with low attack complexity, requiring low privileges and no user interaction. The primary impact is limited to confidentiality, as it allows for information leakage without affecting integrity or availability. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.8.1CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:*:rev7:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.