CVE-2020-11537: SQL Injection
Published Apr 15, 2020
·Updated
A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.
Affected Software
1 affected component
Onlyoffice Document Server=5.5.0
Event History
Apr 15, 2020
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11537?
CVE-2020-11537 is classified as a critical vulnerability due to the potential for arbitrary SQL query execution.
2
How do I fix CVE-2020-11537?
To fix CVE-2020-11537, upgrade ONLYOFFICE Document Server to version 5.5.1 or later.
3
What type of vulnerability is CVE-2020-11537?
CVE-2020-11537 is a SQL Injection vulnerability that affects the DocID parameter in the Websocket API.
4
Which software versions are affected by CVE-2020-11537?
ONLYOFFICE Document Server version 5.5.0 is affected by CVE-2020-11537.
5
Can CVE-2020-11537 lead to data breaches?
Yes, CVE-2020-11537 can potentially allow attackers to manipulate and access sensitive data stored in the database.