Impact
The vulnerable endpoint ActionUploadExcelWithUrl in the General Module of O2OA allows an attacker to supply a crafted fileUrl argument that the server blindly fetches, resulting in a server‑side request forgery. This flaw can be exploited remotely and has published exploits, potentially allowing attackers to retrieve internal resources or interact with services that are otherwise inaccessible from the outside. The damage includes sensitive data exposure, potential privilege escalation, and indirect denial of service if internal resources are overloaded.
Affected Systems
All Deployments of the O2OA open‑source platform running versions up to and including 10.0.1‑ce are affected. The flaw resides in the /x_general_assemble_control/jaxrs/excel/upload/with/url endpoint of the General Module. Upgrades beyond 10.0.1‑ce or the removal of the vulnerable endpoint will eliminate the issue.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact. Although EPSS data is unavailable, the existence of a publicly available exploit and the remote nature of the attack elevate the risk. The vulnerability is not yet listed in the CISA KEV catalog. An attacker can mount the SSRF attack from a remote host, potentially accessing internal systems or services, provided the server can reach them. Because the flaw involves user‑supplied input, it is likely exploitable on any installation without additional hardening.
OpenCVE Enrichment