VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
Imported from official source
Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. …
This version
- Version
- 1 of 3
- Recorded
- September 15, 2026 20:57
- Change
- Initial
- Content hash
9a11396b13bbaa44b5c6a311461af90e- All versions
- Revision history