First published: Tue Jan 12 2021(Updated: )
OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-xchange Open-xchange Appsuite | <=7.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-23927.
The title of this vulnerability is 'OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.'
The severity of this vulnerability is medium, with a severity value of 6.4.
Open-xchange Open-xchange Appsuite up to and including version 7.10.4 are affected by this vulnerability.
The vulnerability can be exploited by sending a maliciously crafted URL containing an @ character in an appsuite/api/oauth/proxy PUT request.