VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
Imported from official source
Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. …
This version
- Version
- 2 of 3
- Recorded
- September 18, 2026 09:42
- Change
- Imported change
- Content hash
1326ea1db8f790d578ab3e4df6f38748- All versions
- Revision history