CVE | CVE-2021-43446 |
CVE Ordinal Value | 220507 |
Published Date | 2023-01-23T15:15Z |
Modified Date | 2023-01-23T17:17Z |
Description | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://github.com/ONLYOFFICE/server |
Reference Description | MISC https://github.com/ONLYOFFICE/server |
Reference URL | https://onlyoffice.com/ |
Reference Description | MISC https://onlyoffice.com/ |
Reference URL | https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/ |
Reference Description | MISC https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/ |
Sources | NIST MITRE |
Note
- No CVSS data for this CVE