Impact
Docs before version 5.4.1 does not close websocket collaboration connections when a user’s access to the parent document is revoked. The result is that the attacker, who had previously joined the document, retains both read and write capabilities to any sub‑documents through the still‑open connection, enabling data exfiltration or tampering without re‑authentication.
Affected Systems
The vulnerability affects suitenumerique Docs releases earlier than 5.4.1. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 7.6 indicates a moderate to high severity. The EPSS score of less than 1% reflects a low current exploitation likelihood, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is inferred to be remote, through an existing WebSocket session that remains active after an access revocation. An attacker would need to have previously accessed the parent document and maintain an open session to exploit the flaw. Mitigation requires closing those sessions to prevent further unauthorized activity.
OpenCVE Enrichment