CVE-2021-25830
Summary
| CVE | CVE-2021-25830 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-01 16:15:00 UTC |
| Updated | 2021-03-15 19:53:00 UTC |
| Description | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Onlyoffice | Document Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - ONLYOFFICE/core: Server core components which are a part of ONLYOFFICE Document Server | MISC | github.com | Product |
| poc_exploits/ONLYOFFICE/CVE-2021-25830 at master · merrychap/poc_exploits · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| GitHub - ONLYOFFICE/DocumentServer: ONLYOFFICE Docs is a free collaborative online office suite comprising viewers and editors for texts, spreadsheets and presentations, forms and PDF, fully compatible with Office Open XML formats: .docx, .xlsx, .pptx and enabling collaborative editing in real time. | MISC | github.com | Product |
| core/UniFill.cpp at v5.6.4.13 · ONLYOFFICE/core · GitHub | MISC | github.com | Third Party Advisory |
| core/BinaryFileReaderWriter.cpp at v5.6.4.13 · ONLYOFFICE/core · GitHub | MISC | github.com | Third Party Advisory |
| core/BinaryFileReaderWriter.cpp at v5.6.4.13 · ONLYOFFICE/core · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.