Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 03 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to 25.04.702, Collabora Online has a Configuration-Dependent RCE (OS Command Injection) in richdocumentscode proxy. Users of Nextcloud with Collabora Online - Built-in CODE Server app can be vulnerable to attack via proxy.php and an intermediate reverse proxy. This vulnerability is fixed in 25.04.702. | |
| Title | Configuration-Dependent RCE (OS Command Injection) in richdocumentscode proxy | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-03T18:51:19.697Z
Reserved: 2025-11-24T23:01:29.677Z
Link: CVE-2025-66208
Updated: 2025-12-03T18:51:11.525Z
Status : Received
Published: 2025-12-03T19:15:57.793
Modified: 2025-12-03T19:15:57.793
Link: CVE-2025-66208
No data.
OpenCVE Enrichment
No data.