First published: Mon Sep 09 2024(Updated: )
ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONLYOFFICE Document Server | <8.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.