Filtered by vendor Onlyoffice
Subscriptions
Filtered by product Server
Subscriptions
Total
6 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-43449 | 1 Onlyoffice | 1 Server | 2024-11-21 | 8.1 High |
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and serve arbitrary URLs as a document. | ||||
CVE-2021-43448 | 1 Onlyoffice | 1 Server | 2024-11-21 | 5.3 Medium |
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known. | ||||
CVE-2021-43447 | 1 Onlyoffice | 1 Server | 2024-11-21 | 7.5 High |
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication. | ||||
CVE-2021-43446 | 1 Onlyoffice | 1 Server | 2024-11-21 | 6.1 Medium |
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used. | ||||
CVE-2021-43445 | 1 Onlyoffice | 1 Server | 2024-11-21 | 9.8 Critical |
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key. | ||||
CVE-2021-43444 | 1 Onlyoffice | 1 Server | 2024-11-21 | 7.5 High |
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key. |
Page 1 of 1.