CVE-2022-24406: SSRF
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24406?
CVE-2022-24406 is a vulnerability in OX App Suite through 7.10.6 that allows server-side request forgery (SSRF) due to predictable multipart/form-data boundaries.
What is SSRF?
SSRF stands for server-side request forgery. It is a vulnerability that allows an attacker to send arbitrary requests from the vulnerable server to other internal or external systems.
What is the severity of CVE-2022-24406?
CVE-2022-24406 is classified as a medium severity vulnerability with a severity score of 6.5.
How can CVE-2022-24406 be exploited?
CVE-2022-24406 can be exploited by an attacker by manipulating the multipart/form-data boundaries to perform unauthorized requests to internal system APIs.
Is there a fix or patch available for CVE-2022-24406?
At the moment, there is no information on an official fix or patch for CVE-2022-24406. It is recommended to monitor the vendor's website for any updates or security advisories.