ONLYOFFICE Document Server
cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*
- < 8.0.1
A path traversal vulnerability has been identified in ONLYOFFICE Document Server versions prior to 8.0.1. This vulnerability allows remote attackers to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint. Exploitation of this issue could lead to unauthorized access to sensitive files and potentially cause a denial-of-service condition.
Exploitation of this vulnerability could result in unauthorized access to sensitive files, with the possibility of causing a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.