CVE-2021-28060

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-28060
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-28060.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-28060
Published
2021-04-14T17:15:14.083Z
Modified
2025-11-14T11:34:33.500094Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.

References

Affected packages

Git / github.com/intermesh/groupoffice

Affected ranges

Type
GIT
Repo
https://github.com/intermesh/groupoffice
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v6.*

v6.2.85
v6.2.87
v6.2.88
v6.2.89
v6.2.90
v6.2.91
v6.2.92
v6.2.93
v6.2.94
v6.2.95
v6.3.1
v6.3.10
v6.3.11
v6.3.12
v6.3.14
v6.3.15
v6.3.16
v6.3.17
v6.3.18
v6.3.19
v6.3.2
v6.3.20
v6.3.21
v6.3.29
v6.3.3
v6.3.30
v6.3.31
v6.3.32
v6.3.33
v6.3.34
v6.3.35
v6.3.36
v6.3.37
v6.3.38
v6.3.4
v6.3.41
v6.3.42
v6.3.43
v6.3.44
v6.3.45
v6.3.47
v6.3.48
v6.3.49
v6.3.5
v6.3.50
v6.3.6
v6.3.7
v6.3.71
v6.3.72
v6.3.73
v6.3.74
v6.3.75
v6.3.76
v6.3.77
v6.3.78
v6.3.79
v6.3.8
v6.3.80
v6.3.81
v6.3.93
v6.3.94
v6.4.156
v6.4.157
v6.4.158
v6.4.159
v6.4.160
v6.4.161
v6.4.162
v6.4.165
v6.4.170
v6.4.171
v6.4.172
v6.4.173
v6.4.174
v6.4.175
v6.4.176
v6.4.177
v6.4.178
v6.4.179
v6.4.180
v6.4.181
v6.4.182
v6.4.183
v6.4.184
v6.4.185
v6.4.186
v6.4.187
v6.4.188
v6.4.189
v6.4.190
v6.4.191
v6.4.192
v6.4.193
v6.4.194
v6.4.195
v6.4.196
v6.4.21
v6.4.22
v6.4.23
v6.4.25
v6.4.26
v6.4.27
v6.4.28
v6.4.29
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.36
v6.4.37
v6.4.38
v6.4.39
v6.4.40
v6.4.41
v6.4.42
v6.4.43
v6.4.44
v6.4.45
v6.4.49
v6.4.50
v6.4.51