Collabora Online is a collaborative online office suite based on LibreOffice. A stored cross-site scripting vulnerability was found in Collabora Online. An attacker could create a document with an XSS payload in document text referenced by field which, if hovered over to produce a tooltip, could be executed by the user's browser. Users should upgrade to Collabora Online 23.05.10.1 or higher. Earlier series of Collabora Online, 22.04, 21.11, etc. are unaffected.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Sep 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Collaboraoffice
Collaboraoffice collabora Online
CPEs cpe:2.3:a:collaboraoffice:collabora_online:*:*:*:*:*:*:*:*
Vendors & Products Collaboraoffice
Collaboraoffice collabora Online

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T01:10:54.093Z

Reserved: 2024-03-18T17:07:00.092Z

Link: CVE-2024-29182

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:54.093Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-04T15:15:38.847

Modified: 2025-09-23T00:54:18.703

Link: CVE-2024-29182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.