OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15002
Reference (s):
- https://seclists.org/fulldisclosure/2020/Oct/20
- https://www.open-xchange.com/

