First published: Thu Jun 22 2023(Updated: )
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONLYOFFICE | <12.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34939 is classified as a critical severity vulnerability due to its potential for remote code execution.
To fix CVE-2023-34939, upgrade your OnlyOffice Community Server to version 12.5.2 or later.
CVE-2023-34939 affects the UploadProgress.ashx component within the OnlyOffice Community Server.
Yes, CVE-2023-34939 allows for remote code execution, making it possible for attackers to exploit it without local access.
The exploitation of CVE-2023-34939 could lead to unauthorized access and control over the system, compromising data integrity and confidentiality.