Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18164 | ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response. |
Solution
The vendor provides a patched version v8.3.2 (or higher) which can be downloaded from: https://github.com/ONLYOFFICE/DocumentServer/
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 18 Jun 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 12 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Thu, 12 Jun 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response. | |
| Title | Reflected Cross-Site Scripting in ONLYOFFICE Docs (DocumentServer) | |
| Weaknesses | CWE-79 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2025-06-18T04:08:26.144Z
Reserved: 2025-05-28T09:59:37.753Z
Link: CVE-2025-5301
Updated: 2025-06-18T04:08:26.144Z
Status : Awaiting Analysis
Published: 2025-06-12T08:15:23.603
Modified: 2025-06-18T05:15:50.287
Link: CVE-2025-5301
No data.
OpenCVE Enrichment
No data.
EUVD