PT-2023-12452 · Unknown · Onlyoffice

Iain Wallace

·

Published

2023-01-23

·

Updated

2025-04-02

·

CVE-2021-43448

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ONLYOFFICE all versions as of 2021-11-08
Description The issue is related to Improper Input Validation, which can be exploited if the document id is known, allowing an attacker to spoof user names who interact with a document.
Recommendations For all versions as of 2021-11-08, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-43448

Affected Products

Onlyoffice