CVE-2020-12644 β€” Server-Side Request Forgery in Appsuite

Severity
5.0MEDIUMNVD
EPSS
0.1%
top 64.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Latest updateMay 24

Description

OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 3.1 | Impact: 1.4

Affected Packages1 packages

πŸ”΄Vulnerability Details

2
GHSA
GHSA-8jwm-9cwx-jcfq: OX App Suite 7β†—2022-05-24
β–Ά
CVEList
CVE-2020-12644: OX App Suite 7β†—2020-08-31
β–Ά
CVE-2020-12644 β€” Server-Side Request Forgery | cvebase