CVE-2021-25833: Path Traversal
Published Mar 1, 2021
·Updated
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.
Affected Software
1 affected component
Onlyoffice Document Server>=4.2.0.71<=5.6.0.21
Event History
Mar 1, 2021
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
Description
Frequently Asked Questions
1
What is CVE-2021-25833 about?
A file extension handling issue in ONLYOFFICE DocumentServer allows an attacker to control the file extension through request data and overwrite files.
2
How severe is CVE-2021-25833?
CVE-2021-25833 has a severity rating of 9.8 (Critical).
3
How can I mitigate CVE-2021-25833?
To mitigate CVE-2021-25833, update ONLYOFFICE DocumentServer to a version beyond 5.6.0.21 or apply patches provided by the vendor.