CVE-2023-50883

ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.
Configurations

Configuration 1 (hide)

cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*

History

20 Sep 2024, 15:18

Type Values Removed Values Added
References () https://www.onlyoffice.com/ - () https://www.onlyoffice.com/ - Product
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-027.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-027.txt - Exploit, Third Party Advisory
References () https://www.syss.de/pentest-blog/cross-site-scripting-schwachstelle-in-onlyoffice-docs-syss-2023-027 - () https://www.syss.de/pentest-blog/cross-site-scripting-schwachstelle-in-onlyoffice-docs-syss-2023-027 - Third Party Advisory
First Time Onlyoffice document Server
Onlyoffice
CPE cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*

10 Sep 2024, 15:35

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-09 20:15

Updated : 2024-09-20 15:18


NVD link : CVE-2023-50883

Mitre link : CVE-2023-50883

CVE.ORG link : CVE-2023-50883


JSON object : View

Products Affected

onlyoffice

  • document_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')