Collabora Online is a collaborative online office suite based on LibreOffice. A stored cross-site scripting vulnerability was found in Collabora Online. An attacker could create a document with an XSS payload in document text referenced by field which, if hovered over to produce a tooltip, could be executed by the user's browser. Users should upgrade to Collabora Online 23.05.10.1 or higher. Earlier series of Collabora Online, 22.04, 21.11, etc. are unaffected.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-04-04T14:48:16.705Z
Updated: 2024-08-02T01:10:54.093Z
Reserved: 2024-03-18T17:07:00.092Z
Link: CVE-2024-29182
Vulnrichment
Updated: 2024-08-02T01:10:54.093Z
NVD
Status : Awaiting Analysis
Published: 2024-04-04T15:15:38.847
Modified: 2024-04-04T16:33:06.610
Link: CVE-2024-29182
Redhat
No data.