← Back

CVE-2021-26699

nvd nist
Published: Jul 22, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.

Affected (56)

1 product
Open Xchange Appsuite
Configuration A
56 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Version 7.10.3
Version 7.10.3 patch_release5547
Version 7.10.3 patch_release5572
Version 7.10.3 patch_release5623
Version 7.10.3 patch_release5653
Version 7.10.3 patch_release5677
Version 7.10.3 patch_release5720
Version 7.10.3 rev10
Version 7.10.3 rev11
Version 7.10.3 rev12
Version 7.10.3 rev13
Version 7.10.3 rev14
Version 7.10.3 rev15
Version 7.10.3 rev16
Version 7.10.3 rev17
Version 7.10.3 rev18
Version 7.10.3 rev19
Version 7.10.3 rev1
Version 7.10.3 rev20
Version 7.10.3 rev21
Version 7.10.3 rev22
Version 7.10.3 rev23
Version 7.10.3 rev24
Version 7.10.3 rev25
Version 7.10.3 rev26
Version 7.10.3 rev27
Version 7.10.3 rev28
Version 7.10.3 rev29
Version 7.10.3 rev2
Version 7.10.3 rev30
Version 7.10.3 rev31
Version 7.10.3 rev3
Version 7.10.3 rev4
Version 7.10.3 rev5
Version 7.10.3 rev6
Version 7.10.3 rev7
Version 7.10.3 rev8
Version 7.10.3 rev9
Version 7.10.4
Version 7.10.4 rev10
Version 7.10.4 rev11
Version 7.10.4 rev12
Version 7.10.4 rev13
Version 7.10.4 rev14
Version 7.10.4 rev15
Version 7.10.4 rev16
Version 7.10.4 rev17
Version 7.10.4 rev1
Version 7.10.4 rev2
Version 7.10.4 rev3
Version 7.10.4 rev4
Version 7.10.4 rev5
Version 7.10.4 rev6
Version 7.10.4 rev7
Version 7.10.4 rev8
Version 7.10.4 rev9

References (8)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.