VYPR

CODE

by Collaboraonline

CVEs (1)

  • CVE-2020-12432MedJul 21, 2020
    risk 0.40cvss 6.1epss 0.01

    The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage. The…