Historical version

This is version 2, as it stood on . It is not what this organization currently publishes — read the current version.

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

CERT Coordination Center Version 2 imported change

Imported from official source

Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. …

This version

Version
2 of 3
Recorded
September 18, 2026 09:42
Change
Imported change
Content hash
1326ea1db8f790d578ab3e4df6f38748
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.