CVE-2024-47222

New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.
Configurations

Configuration 1 (hide)

cpe:2.3:a:myoffice:my_office_sdk:*:*:*:*:*:*:*:*

History

30 Sep 2024, 14:02

Type Values Removed Values Added
CPE cpe:2.3:a:myoffice:my_office_sdk:*:*:*:*:*:*:*:*
CWE CWE-918
References () https://myoffice.ru/ - () https://myoffice.ru/ - Product
References () https://support.myoffice.ru/products/myoffice-sdk/ - () https://support.myoffice.ru/products/myoffice-sdk/ - Product
First Time Myoffice
Myoffice my Office Sdk
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 a 2.8 permite SSRF mediante la manipulación de solicitudes desde el almacenamiento de documentos externo mediante el protocolo MS-WOPI.

23 Sep 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-23 20:15

Updated : 2024-09-30 14:02


NVD link : CVE-2024-47222

Mitre link : CVE-2024-47222

CVE.ORG link : CVE-2024-47222


JSON object : View

Products Affected

myoffice

  • my_office_sdk
CWE
CWE-918

Server-Side Request Forgery (SSRF)