The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses.
CVE-2018-5752
Score 8.8 from GitHub Security Advisory (severity: HIGH) published 2022-05-14. NVD baseline CVSS 8.8; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.8
- EG Score
- 8.8(medium)
- EG Risk
- —
- EPSS
- 94.3%
- KEV
- Not listed
Published
June 16, 2018
Last Modified
November 21, 2024
References (6)
- cve@mitrehttp://packetstormsecurity.com/files/148118/OX-App-Suite-7.8.4-XSS-Privilege-Management-SSRF-Traversal.html
- cve@mitrehttp://seclists.org/fulldisclosure/2018/Jun/23
- cve@mitrehttps://www.exploit-db.com/exploits/44881/
- af854a3a-2127-422b-91ae-364da2661108http://packetstormsecurity.com/files/148118/OX-App-Suite-7.8.4-XSS-Privilege-Management-SSRF-Traversal.html
- af854a3a-2127-422b-91ae-364da2661108http://seclists.org/fulldisclosure/2018/Jun/23
- af854a3a-2127-422b-91ae-364da2661108https://www.exploit-db.com/exploits/44881/
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Publicly available exploits
(1 reference)Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-44881First seen Jun 12, 2018
OX App Suite 7.8.4 - Multiple Vulnerabilities
Open source ↗
Frequently asked(5)
What is CVE-2018-5752?
When was CVE-2018-5752 disclosed?
Is CVE-2018-5752 actively exploited?
What is the CVSS score of CVE-2018-5752?
How do I remediate CVE-2018-5752?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2018-5752
Is Your Infrastructure Affected by CVE-2018-5752?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.