Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known
Metrics
Affected Vendors & Products
References
History
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-xchange
Open-xchange ox App Suite |
|
| Vendors & Products |
Open-xchange
Open-xchange ox App Suite |
Thu, 27 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published: 2025-11-27T09:23:09.153Z
Updated: 2025-11-27T09:23:09.153Z
Reserved: 2025-09-08T14:22:28.104Z
Link: CVE-2025-59025
No data.
Status : Received
Published: 2025-11-27T10:15:51.830
Modified: 2025-11-27T10:15:51.830
Link: CVE-2025-59025
No data.