ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-18164 ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
Fixes

Solution

The vendor provides a patched version v8.3.2 (or higher) which can be downloaded from: https://github.com/ONLYOFFICE/DocumentServer/


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00125}

epss

{'score': 0.00146}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00108}

epss

{'score': 0.00125}


Wed, 18 Jun 2025 05:45:00 +0000

Type Values Removed Values Added
References

Thu, 12 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Jun 2025 08:15:00 +0000

Type Values Removed Values Added
Description ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
Title Reflected Cross-Site Scripting in ONLYOFFICE Docs (DocumentServer)
Weaknesses CWE-79
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-06-18T04:08:26.144Z

Reserved: 2025-05-28T09:59:37.753Z

Link: CVE-2025-5301

cve-icon Vulnrichment

Updated: 2025-06-18T04:08:26.144Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-12T08:15:23.603

Modified: 2025-06-18T05:15:50.287

Link: CVE-2025-5301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses