ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 18 Jun 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 12 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Thu, 12 Jun 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response. | |
| Title | Reflected Cross-Site Scripting in ONLYOFFICE Docs (DocumentServer) | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: SEC-VLab
Published: 2025-06-12T07:59:05.650Z
Updated: 2025-06-18T04:08:26.144Z
Reserved: 2025-05-28T09:59:37.753Z
Link: CVE-2025-5301
Updated: 2025-06-18T04:08:26.144Z
Status : Awaiting Analysis
Published: 2025-06-12T08:15:23.603
Modified: 2025-06-18T05:15:50.287
Link: CVE-2025-5301
No data.