Description
ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.
Published: 2020-06-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3703-1 libreoffice security update
Ubuntu USN Ubuntu USN USN-5694-1 LibreOffice vulnerabilities
History

No history.

Subscriptions

Fedoraproject Fedora
Libreoffice Libreoffice
Opensuse Leap
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: Document Fdn.

Published:

Updated: 2024-09-16T22:25:46.168Z

Reserved: 2020-05-12T00:00:00.000Z

Link: CVE-2020-12803

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-08T16:15:10.057

Modified: 2024-11-21T05:00:19.277

Link: CVE-2020-12803

cve-icon Redhat

Severity : Low

Publid Date: 2020-06-08T00:00:00Z

Links: CVE-2020-12803 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses