VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

CERT Coordination Center Version 3 imported change current

Imported from official source

A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. …

This version

Version
3 of 3
Recorded
September 24, 2026 20:00
Change
Imported change
Content hash
ca6be60223247d7272cb9bcc72e7138c
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.