ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
History

Wed, 18 Jun 2025 05:45:00 +0000

Type Values Removed Values Added
References

Thu, 12 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Jun 2025 08:15:00 +0000

Type Values Removed Values Added
Description ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
Title Reflected Cross-Site Scripting in ONLYOFFICE Docs (DocumentServer)
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published: 2025-06-12T07:59:05.650Z

Updated: 2025-06-18T04:08:26.144Z

Reserved: 2025-05-28T09:59:37.753Z

Link: CVE-2025-5301

cve-icon Vulnrichment

Updated: 2025-06-18T04:08:26.144Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-12T08:15:23.603

Modified: 2025-06-18T05:15:50.287

Link: CVE-2025-5301

cve-icon Redhat

No data.