CVE-2021-25830: Critical severity onlyoffice vulnerability
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-25830?
CVE-2021-25830 has a high severity rating as it involves file extension handling issues that can lead to remote code execution.
How do I fix CVE-2021-25830?
To fix CVE-2021-25830, you should upgrade ONLYOFFICE DocumentServer to the latest version beyond 5.6.4.13.
What versions of ONLYOFFICE DocumentServer are affected by CVE-2021-25830?
CVE-2021-25830 affects ONLYOFFICE DocumentServer versions from 4.2.0.236 to 5.6.4.13.
What type of attack can exploit CVE-2021-25830?
CVE-2021-25830 can be exploited through crafted files requested for conversion from DOCT to DOCX format.
Is CVE-2021-25830 a remote or local exploit?
CVE-2021-25830 is considered a remote exploit, as it requires an attacker to send a specially crafted file to the server.