CVE | CVE-2021-43447 |
CVE Ordinal Value | 220508 |
Published Date | 2023-01-23T15:15Z |
Modified Date | 2023-01-23T17:17Z |
Description | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://github.com/ONLYOFFICE/server |
Reference Description | MISC https://github.com/ONLYOFFICE/server |
Reference URL | https://www.onlyoffice.com/ |
Reference Description | MISC https://www.onlyoffice.com/ |
Reference URL | https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/ |
Reference Description | MISC https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/ |
Sources | NIST MITRE |
Note
- No CVSS data for this CVE