Impact
The vulnerability allows an authenticated administrator to manipulate the document server URL parameter at the /apps/onlyoffice/ajax/settings/address endpoint so the ownCloud server initiates outbound HTTP requests to an arbitrary exposed to the administrator, the attacker can direct to internal hosts or to localhost, enabling reconnaissance and more precise scanning of internal application services via differing responses.
Affected Systems
The vulnerability affects the ONLYOFFICE ownCloud Integration plugin for Ascensio System SIA, specifically version 9.12. No other versions are mentioned in the CNA or the advisory.
Risk and Exploitability
The flaw is categorized as an SSRF. It is only exploitable by users who have administrative privileges, giving the attacker the ability to discover internal hosts and open ports and potentially access services that are otherwise blocked from the Internet. The CVSS score is 6.5, the EPSS score is <1%, and the issue is not listed in the CISA KEV catalog, indicating a lower likelihood of immediate widespread exploitation. Nonetheless, because the attack requires authentication, the internal reconnaissance capabilities still warrant prompt remedial action.
OpenCVE Enrichment