CVE-2020-12644

MEDIUM

OX App Suite <=7.10.3 - Server-Side Request Forgery via Mail and Folder APIs

Title source: manual
STIX 2.1

Description

OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://www.open-xchange.com/
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/fulldisclosure/2020/Aug/14

Scores

CVSS v3 5.0
EPSS 0.0015
EPSS Percentile 35.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Details

CWE
CWE-918
Status published
Products (1)
open-xchange/open-xchange_appsuite < 7.10.3
Published Aug 31, 2020
Tracked Since Feb 18, 2026