A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of the component URL Fetching. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-7291 is a server-side request forgery (SSRF) vulnerability in o2oa up to version 10.0 affecting the FileAction component's URL fetching functionality. Remote attackers can manipulate the fileUrl parameter to perform unauthorized requests, with public exploits already available.
تم تحديد ضعف في o2oa حتى الإصدار 10.0 يؤثر على وظيفة FileAction في مكون جلب عناوين URL. يمكن للمهاجمين البعيدين استغلال هذه الثغرة عن طريق التلاعب بمعامل fileUrl لتنفيذ طلبات غير مصرح بها على الخادم.
A server-side request forgery vulnerability exists in o2oa versions up to 10.0 in the FileAction component. Attackers can remotely exploit this by manipulating the fileUrl parameter to make unauthorized server requests.
Update o2oa to a version beyond 10.0 that includes security patches for SSRF vulnerabilities. Implement input validation and sanitization for the fileUrl parameter. Apply network-level controls to restrict outbound requests from the application server. Monitor and log all URL fetching activities for suspicious patterns.
قم بتحديث o2oa إلى إصدار أحدث من 10.0 يتضمن تصحيحات أمان. طبق التحقق من صحة المدخلات وتنظيفها لمعامل fileUrl. طبق عناصر تحكم على مستوى الشبكة لتقييد الطلبات الصادرة. راقب وسجل جميع أنشطة جلب عناوين URL.