CVE-2020-11534: Input Validation
An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the NSFileDownloader function to pass parameters to a binary (such as curl or wget) and remotely execute code on a victim's server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11534?
CVE-2020-11534 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2020-11534?
To fix CVE-2020-11534, upgrade ONLYOFFICE Document Server to version 5.5.1 or later.
What does CVE-2020-11534 allow attackers to do?
CVE-2020-11534 allows attackers to remotely execute code on a victim's server using a specially crafted .docx file.
Which version of ONLYOFFICE Document Server is affected by CVE-2020-11534?
ONLYOFFICE Document Server version 5.5.0 is affected by CVE-2020-11534.
Is CVE-2020-11534 related to file handling vulnerabilities?
Yes, CVE-2020-11534 is related to vulnerabilities in handling malicious .docx files, specifically within the NSFileDownloader function.