CVE-2021-43446: XSS
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43446?
CVE-2021-43446 is classified as a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2021-43446?
To mitigate CVE-2021-43446, upgrade to a version of ONLYOFFICE server newer than 7.0.0.49.
What components are affected by CVE-2021-43446?
CVE-2021-43446 affects all versions of ONLYOFFICE server up to and including 7.0.0.49.
What type of vulnerability is CVE-2021-43446?
CVE-2021-43446 is a cross-site scripting (XSS) vulnerability that can be exploited through the macros feature in the ONLYOFFICE document editor.
Can CVE-2021-43446 lead to remote code execution?
While CVE-2021-43446 itself focuses on XSS, subsequent exploitation could potentially lead to remote code execution in certain scenarios.