CVE-2023-30188: High severity Onlyoffice Document Server vulnerability
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this memory exhaustion vulnerability in ONLYOFFICE Document Server?
The vulnerability ID for this memory exhaustion vulnerability in ONLYOFFICE Document Server is CVE-2023-30188.
What is the severity of CVE-2023-30188?
The severity of CVE-2023-30188 is high with a CVSS score of 7.5.
What is the affected software for CVE-2023-30188?
The affected software for CVE-2023-30188 is ONLYOFFICE Document Server versions 4.0.3 through 7.3.2.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers using a crafted JavaScript file to cause a denial of service.
Are there any references for CVE-2023-30188?
Yes, some references for CVE-2023-30188 include: (1) http://onlyoffice.com, (2) https://gist.github.com/merrychap/25eba8c4dd97c9e545edad1b8f0eadc2, and (3) https://github.com/ONLYOFFICE/DocumentServer.