CVE-2020-15002
OX App Suite / OX Documents 7.10.3 XSS / Server-Side Request Forgery
Severity Score
5.0
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
OX App Suite versiones hasta 7.10.3, permite un ataque de tipo SSRF por medio de la API de mensajes /ajax/messaging/message
OX App Suite and OX Documents versions 7.10.3 and some prior versions suffer from information exposure, server-side request forgery, and cross site scripting vulnerabilities.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-06-24 CVE Reserved
- 2020-10-19 CVE Published
- 2020-12-14 First Exploit
- 2024-08-04 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.open-xchange.com | Product |
URL | Date | SRC |
---|---|---|
https://github.com/skr0x1c0/SSRF-CVE-2020-15002 | 2020-12-14 | |
https://github.com/skr0x1c0/Blind-SSRF-CVE-2020-15002 | 2020-12-14 | |
https://seclists.org/fulldisclosure/2020/Oct/20 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | <= 7.10.3 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version " <= 7.10.3" | - |
Affected
|