CVE-2026-105438: O2OA General url ActionUploadExcelWithUrl server-side request forgery
A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /xgeneralassemblecontrol/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be considered exposed?
O2OA deployments up to version 10.0.1-ce are affected where the General Module endpoint at /x_general_assemble_control/jaxrs/excel/upload/with/url is available.
What does an attacker need to exploit this issue?
The attack can be performed remotely with low privileges and does not require user interaction. The vulnerable input is the fileUrl argument handled by the ActionUploadExcelWithUrl function.
How likely is active exploitation?
An exploit has been published and may be used. The project was reportedly notified through an issue report but had not responded at the time of the report.