CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It affects Office. It may be remotely exploitable.
CVE
CVE-2021-28060
Severity
MEDIUM
CVSS
5.3
EPSS
1.43%
Office
Original NVD Description
A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.
Related CVEs
Other vulnerabilities affecting the same vendor(s)