CVE-2021-40864: Critical severity Onlyoffice Google Translate Document Server vulnerability
Published Sep 10, 2021
·Updated
The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.
Affected Software
1 affected component
Onlyoffice Google Translate Document Server>=6.1.0<6.3.0.72
Remediation
Event History
Sep 10, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-40864?
The severity of CVE-2021-40864 is rated as medium due to potential cross-site scripting vulnerabilities.
2
How do I fix CVE-2021-40864?
To fix CVE-2021-40864, upgrade the ONLYOFFICE Document Server to version 6.3.0.72 or later.
3
Which versions of ONLYOFFICE Document Server are affected by CVE-2021-40864?
ONLYOFFICE Document Server versions 6.1.x through 6.3.x prior to 6.3.0.72 are affected by CVE-2021-40864.
4
What types of vulnerabilities are associated with CVE-2021-40864?
CVE-2021-40864 is associated with cross-site scripting vulnerabilities due to lack of proper escape calls.
5
Is there any workaround for CVE-2021-40864 if I cannot upgrade?
There are no recommended workarounds for CVE-2021-40864; upgrading is the only effective solution.