CVE-2016-6848: Open-Xchange Appsuite

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a trusted domain without authentication that, if executed by the user, may lead to local code execution.

Affected products

  • Open-Xchange Open-Xchange Appsuite: up to and including 7.8.2

Published 2016-12-15. Last modified 2026-06-17.