Back to Database
Status published
Medium
CVE-2020-17386
Cellopoint CelloOS - Server-Side Request Forgery (SSRF)
Vulnerability Description
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbitrary file on system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-17386
Credits & Attribution
No credits recorded in the NVD database.
More from Cellopoint
View All →CVE-2024-9043
Cellopoint Secure Email Gateway - Buffer Overflow
Critical
9.8
CVE-2024-6744
The SMTP Listener of Secure Email Gateway from Cellopoint does...
Critical
9.8
CVE-2020-17385
Cellopoint CelloOS - Unauthenticated Arbitrary File Disclosure
High
7.5
CVE-2020-17384
Cellopoint CelloOS - Remote Command Execution (RCE)
High
7.2
Affected Vendor
Cellopoint
View all reports →Affected Software
CelloOS
Vulnerable Versions:
0
Timeline
Official Publish:
August 25th, 2020
Last Modified:
May 8th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N