VYPR
High severity7.1NVD Advisory· Published Feb 18, 2022· Updated Jun 17, 2026

CVE-2021-26618

CVE-2021-26618

Description

An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code.

Affected products

2
  • ToOffice/ToWordllm-create
  • TmaxSoft Co., Ltd/ToOfficev5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.