Product: Open-Xchange AppSuite Vendor: Open-Xchange GmbH Internal reference: 29648 (Bug ID) Vulnerability type: CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page) Vulnerable version: 6.22.4 and earlier Vulnerable component: frontend6 Fixed version: 6.22.3-rev5, 6.22.4-rev12 Report confidence: Confirmed Solution status: Fixed by Vendor Vendor notification: 2013-11-05 Solution date: 2013-11-12 Public disclosure: 2013-11-25 CVE reference: CVE-2013-6242 CVSSv2: 5.7 (AV:N/AC:M/Au:N/C:P/I:N/A:N/E:POC/RL:U/RC:C/CDP:LM/TD:H/CR:ND/IR:ND/AR:ND) Vulnerability Details: Embedding JavaScript code within an E-Mail gets executed when using misplaced closing TITLE tag at the mail subject, followed by