CVE-2021-43447: High severity onlyoffice document server vulnerability
Published Jan 23, 2023
·Updated
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.
Affected Software
1 affected component
ONLYOFFICE Server<=7.0.0.49
Event History
Jan 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-43447.
2
What is the title of this vulnerability?
The title of this vulnerability is 'ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.'
3
What is the severity of CVE-2021-43447?
The severity of CVE-2021-43447 is high with a CVSS score of 7.5.
4
What is the affected software by CVE-2021-43447?
The affected software by CVE-2021-43447 is Onlyoffice Server version up to and including 7.0.0.49.
5
How can an attacker exploit CVE-2021-43447?
An attacker can exploit CVE-2021-43447 by bypassing authentication in the document editor to edit documents without authentication.