CVE-2020-12644 β Server-Side Request Forgery in Appsuite
Severity
5.0MEDIUMNVD
EPSS
0.1%
top 64.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Latest updateMay 24
Description
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 3.1 | Impact: 1.4