OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.Referenceshttps://open-xchange.comhttps://seclists.org/fulldisclosure/2022/Nov/18