Логотип exploitDog
bind:CVE-2021-25833
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25833

Количество 2

Количество 2

nvd логотип

CVE-2021-25833

почти 5 лет назад

A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-f4rq-cvc9-g327

больше 3 лет назад

12345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-25833

A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.

CVSS3: 9.8
8%
Низкий
почти 5 лет назад
github логотип
GHSA-f4rq-cvc9-g327

12345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890

8%
Низкий
больше 3 лет назад

Уязвимостей на страницу