OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12645
Reference (s):
- https://seclists.org/fulldisclosure/2020/Aug/14
- https://www.open-xchange.com/

