CVE-2020-24700: Open-Xchange Appsuite

Medium severity, CVSS 5.4. EPSS: 1.2% chance of exploitation in the next 30 days.

OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

Affected products

  • Open-Xchange Open-Xchange Appsuite: up to and including 7.10.3

Published 2021-01-12. Last modified 2026-06-17.