5.8

CVE-2021-26699

OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.

Data is provided by the National Vulnerability Database (NVD)
Open-xchangeOpen-xchange Appsuite Version7.10.3 Update-
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updatepatch_release5547
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updatepatch_release5572
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updatepatch_release5623
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updatepatch_release5653
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updatepatch_release5677
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updatepatch_release5720
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev1
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev10
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev11
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev12
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev13
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev14
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev15
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev16
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev17
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev18
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev19
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev2
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev20
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev21
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev22
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev23
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev24
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev25
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev26
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev27
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev28
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev29
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev3
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev30
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev31
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev4
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev5
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev6
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev7
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev8
Open-xchangeOpen-xchange Appsuite Version7.10.3 Updaterev9
Open-xchangeOpen-xchange Appsuite Version7.10.4 Update-
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev1
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev10
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev11
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev12
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev13
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev14
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev15
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev16
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev17
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev2
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev3
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev4
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev5
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev6
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev7
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev8
Open-xchangeOpen-xchange Appsuite Version7.10.4 Updaterev9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.47% 0.618
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:N/A:P
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.