CVE-2023-46988: Path Traversal
Published Apr 1, 2025
·Updated
Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).
Affected Software
2 affected components
Onlyoffice Document Server<8.0.1
Onlyoffice Document Server>=7.4.0<8.0.1
Event History
Apr 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46988?
CVE-2023-46988 has a high severity rating as it allows remote attackers to exploit a directory traversal vulnerability.
2
How do I fix CVE-2023-46988?
To fix CVE-2023-46988, upgrade ONLYOFFICE Document Server to version 7.5.1 or later.
3
What versions of ONLYOFFICE Document Server are affected by CVE-2023-46988?
CVE-2023-46988 affects ONLYOFFICE Document Server versions 7.5.0 and earlier.
4
What type of vulnerability is CVE-2023-46988?
CVE-2023-46988 is classified as a directory traversal vulnerability.
5
What could a remote attacker achieve by exploiting CVE-2023-46988?
By exploiting CVE-2023-46988, a remote attacker could obtain sensitive information from the affected system.