CVE-2018-5756 describes an improper access control vulnerability in Open-Xchange OX App Suite versions prior to 7.6.3-rev36, 7.8.2-rev39, 7.8.3-rev44, and 7.8.4-rev22. An authenticated attacker can exploit this flaw by sending a delete action with a task ID to the API, allowing them to delete arbitrary tasks. This vulnerability has a CVSS score of 4.3 (Medium), indicating a low impact on integrity and no impact on confidentiality or availability, with a network attack vector and low attack complexity. While there is an ExploitDB entry (EDB-44881) detailing multiple vulnerabilities in OX App Suite 7.8.4, there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage for this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.6.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:* | ||
7.6.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.3:rev14:*:*:*:*:*:* | ||
7.6.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.3:rev15:*:*:*:*:*:* | ||
7.6.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.3:rev16:*:*:*:*:*:* | ||
7.6.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.3:rev17:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.