CVE-2024-47222

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
23/09/2024
Last modified:
18/03/2025

Description

New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:myoffice:my_office_sdk:*:*:*:*:*:*:*:* 2.2.2 (including) 2.8.0 (including)