4.3
CVE-2022-43699
- EPSS 0.07%
- Published 15.04.2023 02:15:07
- Last modified 06.02.2025 20:15:38
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address).
Data is provided by the National Vulnerability Database (NVD)
Open-xchange ≫ Ox App Suite Version < 7.10.6
Open-xchange ≫ Ox App Suite Version7.10.6 Update-
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev01
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev02
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev03
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev04
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev05
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev06
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev07
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev08
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev09
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev10
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev11
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev12
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev13
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev14
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev15
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev16
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev17
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev18
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev19
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev20
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev21
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev22
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev23
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev24
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev25
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev26
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev27
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev28
Open-xchange ≫ Ox App Suite Version7.10.6 Updaterev29
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.171 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.