// For flags

CVE-2014-5237

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Server-side request forgery (SSRF) vulnerability in the documentconverter component in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allows remote attackers to trigger requests to arbitrary servers and embed arbitrary images via a URL in an embedded image in a Text document, which is not properly handled by the image preview.

Vulnerabilidad de SSRF en el componente documentconverter en Open-Xchange (OX) AppSuite anterior a 7.4.2-rev10 y 7.6.x anterior a 7.6.0-rev10 permite a atacantes remotos provocar solicitudes a servidores arbitrarios y anidar imágenes arbitrarias a través de una URL en una imagen anidiada en un documento de texto, lo que no se maneja debidamente en la vista previa de la imagen.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-08-13 CVE Reserved
  • 2014-09-15 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Open-xchange
Search vendor "Open-xchange"
App Suite
Search vendor "Open-xchange" for product "App Suite"
7.4.2
Search vendor "Open-xchange" for product "App Suite" and version "7.4.2"
rev6
Affected
Open-xchange
Search vendor "Open-xchange"
App Suite
Search vendor "Open-xchange" for product "App Suite"
7.4.2
Search vendor "Open-xchange" for product "App Suite" and version "7.4.2"
rev7
Affected
Open-xchange
Search vendor "Open-xchange"
App Suite
Search vendor "Open-xchange" for product "App Suite"
7.4.2
Search vendor "Open-xchange" for product "App Suite" and version "7.4.2"
rev8
Affected
Open-xchange
Search vendor "Open-xchange"
App Suite
Search vendor "Open-xchange" for product "App Suite"
7.4.2
Search vendor "Open-xchange" for product "App Suite" and version "7.4.2"
rev9
Affected
Open-xchange
Search vendor "Open-xchange"
App Suite
Search vendor "Open-xchange" for product "App Suite"
7.6.0
Search vendor "Open-xchange" for product "App Suite" and version "7.6.0"
rev6
Affected
Open-xchange
Search vendor "Open-xchange"
App Suite
Search vendor "Open-xchange" for product "App Suite"
7.6.0
Search vendor "Open-xchange" for product "App Suite" and version "7.6.0"
rev7
Affected
Open-xchange
Search vendor "Open-xchange"
App Suite
Search vendor "Open-xchange" for product "App Suite"
7.6.0
Search vendor "Open-xchange" for product "App Suite" and version "7.6.0"
rev8
Affected
Open-xchange
Search vendor "Open-xchange"
App Suite
Search vendor "Open-xchange" for product "App Suite"
7.6.0
Search vendor "Open-xchange" for product "App Suite" and version "7.6.0"
rev9
Affected