First published: Mon Jan 23 2023(Updated: )
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Onlyoffice Server | <=7.0.0.49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-43448.
The severity of CVE-2021-43448 is medium with a CVSS score of 5.3.
The affected software is Onlyoffice Server version up to and including 7.0.0.49.
CVE-2021-43448 is an improper input validation vulnerability in Onlyoffice Server that allows an attacker to spoof user names.
Yes, you can find more information about CVE-2021-43448 in the following references: [GitHub](https://github.com/ONLYOFFICE/server), [Nettitude Blog](https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/), [Onlyoffice](https://www.onlyoffice.com/).