← Back

CVE-2013-1648

nvd nist
Published: Sep 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.

Affected (3)

1 product
Open Xchange Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Version 6.20.7
Version 6.22.0
Version 6.22.1

References (2)

Timeline

No history available yet.