CVE-2022-43699: SSRF
OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43699?
The severity of CVE-2022-43699 is medium with a score of 4.3.
What software is affected by CVE-2022-43699?
OX App Suite versions up to and including 7.10.6-rev30 are affected by CVE-2022-43699.
What is SSRF?
SSRF stands for Server-Side Request Forgery, which is a vulnerability that allows an attacker to make requests to internal or external resources on behalf of the vulnerable server.
How can an adversary exploit CVE-2022-43699?
An adversary who controls the DNS records of an external domain can exploit CVE-2022-43699 by attacking the e-mail account discovery feature of OX App Suite.
Where can I get more information about CVE-2022-43699?
You can find more information about CVE-2022-43699 on the official Open-xchange website and the seclists.org mailing list.