Impact
The vulnerability allows an authenticated administrator to manipulate the document server URL parameter at the /apps/onlyoffice/ajax/settings/address endpoint so the ownCloud server initiates outbound HTTP requests to an arbitrary destination before performing validation. Because the endpoint is exposed to the administrator, the attacker can direct the ownCloud server to send requests to internal hosts or to localhost, enabling reconnaissance and more precise scanning of internal application services via differing responses.
Affected Systems
The vulnerability affects the ONLYOFFICE ownCloud Integration plugin for Ascensio System SIA, specifically version 9.12. No other versions are mentioned in the CNA or the advisory.
Risk and Exploitability
The flaw is categorized as an SSRF (CWE‑918). It is only exploitable by users who have administrative privileges, giving the attacker the ability to discover internal hosts and open ports and potentially access services that are otherwise blocked from the Internet. The CVSS score is not provided, EPSS is not available, and the issue is not listed in the CISA KEV catalog, indicating a lower likelihood of immediate widespread exploitation. Nonetheless, because the attack requires authentication, the threat window is limited to internal administrators but internal reconnaissance capabilities still warrant prompt remedial action.
OpenCVE Enrichment