CVE-2022-37313

MEDIUM WAF: Medium
CVSS 5.3 Published: 2022-12-26
CWE-918 CWE-918

OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

WAF Coverage Analysis

Server-Side Request Forgery (SSRF) Medium WAF Coverage

OWASP: A10:2021 SSRF

934xxx - Node.js / Generic Injection
Server-Side Request Forgery (SSRF) Medium WAF Coverage

OWASP: A10:2021 SSRF

934xxx - Node.js / Generic Injection

Affected Software

VendorProductVersion
open-xchangeopen-xchange_appsuiteup to 7.10.5
open-xchangeopen-xchange_appsuite7.10.5
open-xchangeopen-xchange_appsuite7.10.5
open-xchangeopen-xchange_appsuite7.10.5
open-xchangeopen-xchange_appsuite7.10.5
open-xchangeopen-xchange_appsuite7.10.5
open-xchangeopen-xchange_appsuite7.10.5
open-xchangeopen-xchange_appsuite7.10.5
open-xchangeopen-xchange_appsuite7.10.5
open-xchangeopen-xchange_appsuite7.10.5

References

Back to CVE Database