9.8
CVE-2023-30187
- EPSS 1.86%
- Veröffentlicht 14.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:52
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Onlyoffice ≫ Document Server Version >= 4.0.3 <= 7.3.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.86% | 0.764 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://github.com/ONLYOFFICE/DocumentServer
http://onlyoffice.com
https://gist.github.com/merrychap/25eba8c4dd97c9e545edad1b8f0eadc2
https://github.com/ONLYOFFICE/core/blob/8ca40a44ce47a86168327a46db91253cf6bb205d/DesktopEditor/doctrenderer/
https://github.com/ONLYOFFICE/core/blob/8ca40a44ce47a86168327a46db91253cf6bb205d/DesktopEditor/doctrenderer/embed/NativeControlEmbed.cpp#L110
https://github.com/ONLYOFFICE/core/commit/2b6ad83b36afd9845085b536969d366d1d61150a