Medium severity6.1NVD Advisory· Published Jun 12, 2025· Updated Apr 15, 2026
CVE-2025-5301
CVE-2025-5301
Description
ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=8.3.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.