OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15003
Reference (s):
- https://seclists.org/fulldisclosure/2020/Oct/20
- https://www.open-xchange.com/

