CVE-2021-43448: Input Validation
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-43448.
What is the severity of CVE-2021-43448?
The severity of CVE-2021-43448 is medium with a CVSS score of 5.3.
What is the affected software by CVE-2021-43448?
The affected software is Onlyoffice Server version up to and including 7.0.0.49.
What is the description of CVE-2021-43448?
CVE-2021-43448 is an improper input validation vulnerability in Onlyoffice Server that allows an attacker to spoof user names.
Are there any known references for CVE-2021-43448?
Yes, you can find more information about CVE-2021-43448 in the following references: [GitHub](https://github.com/ONLYOFFICE/server), [Nettitude Blog](https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/), [Onlyoffice](https://www.onlyoffice.com/).