VYPR

Docs

by ONLYOFFICE

CVEs (2)

  • CVE-2022-48422HigMar 19, 2023
    risk 0.51cvss 7.8epss 0.00

    ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.

  • CVE-2023-50883MedSep 9, 2024
    risk 0.40cvss 6.1epss 0.01

    ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for…