Vulnerabilities > CVE-2021-26699 - Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite 7.10.3/7.10.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
LOW Summary
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 56 |
Common Weakness Enumeration (CWE)
References
- http://packetstormsecurity.com/files/163527/OX-App-Suite-OX-Guard-OX-Documents-SSRF-Cross-Site-Scripting.html
- http://packetstormsecurity.com/files/163527/OX-App-Suite-OX-Guard-OX-Documents-SSRF-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2021/Jul/33
- http://seclists.org/fulldisclosure/2021/Jul/33
- https://seclists.org/fulldisclosure/2021/Jul/33
- https://seclists.org/fulldisclosure/2021/Jul/33
- https://www.open-xchange.com
- https://www.open-xchange.com