CVE-2023-34939: Path Traversal
Published Jun 22, 2023
·Updated
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.
Affected Software
1 affected component
Onlyoffice Onlyoffice<12.5.2
Event History
Jun 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34939?
CVE-2023-34939 is classified as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2023-34939?
To fix CVE-2023-34939, upgrade your OnlyOffice Community Server to version 12.5.2 or later.
3
What components are affected by CVE-2023-34939?
CVE-2023-34939 affects the UploadProgress.ashx component within the OnlyOffice Community Server.
4
Can CVE-2023-34939 be exploited remotely?
Yes, CVE-2023-34939 allows for remote code execution, making it possible for attackers to exploit it without local access.
5
What are the potential consequences of CVE-2023-34939?
The exploitation of CVE-2023-34939 could lead to unauthorized access and control over the system, compromising data integrity and confidentiality.