PT-2023-12450 · Unknown · Onlyoffice

Iain Wallace

·

Publicado

2023-01-23

·

Atualizado

2025-07-03

·

CVE-2021-43446

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ONLYOFFICE versions prior to the version released after 2021-11-08
Description The issue concerns a Cross Site Scripting (XSS) problem. The "macros" feature of the document editor in ONLYOFFICE allows malicious cross site scripting payloads to be used.
Recommendations For versions prior to the version released after 2021-11-08, consider disabling the "macros" feature of the document editor until a patch is available. Restrict access to the document editor to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-43446

Produtos afetados

Onlyoffice