ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Jun 2025 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 12 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
cvssV3_1
|
Thu, 12 Jun 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response. | |
Title | Reflected Cross-Site Scripting in ONLYOFFICE Docs (DocumentServer) | |
Weaknesses | CWE-79 | |
References |
|

Status: PUBLISHED
Assigner: SEC-VLab
Published: 2025-06-12T07:59:05.650Z
Updated: 2025-06-18T04:08:26.144Z
Reserved: 2025-05-28T09:59:37.753Z
Link: CVE-2025-5301

Updated: 2025-06-18T04:08:26.144Z

Status : Awaiting Analysis
Published: 2025-06-12T08:15:23.603
Modified: 2025-06-18T05:15:50.287
Link: CVE-2025-5301

No data.