CVE-2026-105438 | O2OA up to 10.0.1-ce General url ActionUploadExcelWithUrl fileUrl server-side request forgery (Issue 210)

SecurityVulns

A vulnerability classified as problematic was found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery.

This vulnerability is tracked as CVE-2026-105438. The attack can be launched remotely. Moreover, an exploit is present.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More