Vulnerabilities > CVE-2018-5752 - Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
open-xchange
CWE-918
exploit available

Summary

The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionOX App Suite 7.8.4 - Multiple Vulnerabilities. CVE-2017-17062,CVE-2018-5751,CVE-2018-5752,CVE-2018-5753,CVE-2018-5754,CVE-2018-5755,CVE-2018-5756. Webapps ex...
fileexploits/xml/webapps/44881.txt
idEDB-ID:44881
last seen2018-06-12
modified2018-06-12
platformxml
port
published2018-06-12
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44881/
titleOX App Suite 7.8.4 - Multiple Vulnerabilities
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/148118/oxappsuite-escalatexss.txt
idPACKETSTORM:148118
last seen2018-06-13
published2018-06-08
reporterMartin Heiland
sourcehttps://packetstormsecurity.com/files/148118/OX-App-Suite-7.8.4-XSS-Privilege-Management-SSRF-Traversal.html
titleOX App Suite 7.8.4 XSS / Privilege Management / SSRF / Traversal