PT-2021-16808 · Onlyoffice · Onlyoffice Document Server

Published

2021-03-01

·

Updated

2021-10-29

·

CVE-2021-25833

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ONLYOFFICE DocumentServer versions 4.2.0.71 through 5.6.0.21
Description A file extension handling issue was found in the server module of ONLYOFFICE DocumentServer. The file extension can be controlled by an attacker through the request data, leading to arbitrary file overwriting. This issue allows a remote attacker to obtain remote code execution on DocumentServer.
Recommendations For versions 4.2.0.71 through 5.6.0.21, consider restricting access to the server module until a patch is available. As a temporary workaround, avoid using the vulnerable file extension handling functionality in the request data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25833

Affected Products

Onlyoffice Document Server