AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-6853

MEDIUM · CVSS 6.1 EPSS 2.44% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-12-15 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2016-6853
Severity
MEDIUM
CVSS
6.1
EPSS
2.44%

Original NVD Description

An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on using a specific URL, such script code might get executed. In case of injecting external websites, users might get lured into a phishing scheme. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).