Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4rq-cvc9-g327

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

12345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890

A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.

UPDATE!

EPSS

Процентиль: 92%
0.07618
Низкий

Дефекты

CWE-22
CWE-79

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.

EPSS

Процентиль: 92%
0.07618
Низкий

Дефекты

CWE-22
CWE-79