An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office directory setting pointing to an arbitrary remote network path. This triggers the execution of the soffice binary under the attackers control leading to arbitrary remote code execution (RCE).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-02-28T00:00:00
Updated: 2024-08-02T11:18:36.265Z
Reserved: 2023-02-06T00:00:00
Link: CVE-2023-25266
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2023-02-28T16:15:09.297
Modified: 2023-03-07T22:57:39.193
Link: CVE-2023-25266
Redhat
No data.