Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

CERT Coordination Center Version 1 original

Imported from official source

Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. …

This version

Version
1 of 3
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
9a11396b13bbaa44b5c6a311461af90e
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.