OX App Suite up to and including 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
open-xchange open-xchange appsuite |
||
open-xchange open-xchange appsuite 7.10.5 |
||
open-xchange open-xchange appsuite 7.10.6 |