Vulnerabilities > Open Xchange > Open Xchange Appsuite Backend > 7.10.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-20 | CVE-2023-26435 | Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite Backend It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. | 5.0 |
2023-06-20 | CVE-2023-26436 | Deserialization of Untrusted Data vulnerability in Open-Xchange Appsuite Backend Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. | 8.8 |