The Document Foundation LibreOffice
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*
- >= 24.8, < 24.8.4
A vulnerability in LibreOffice prior to 24.8.4 allows for the exfiltration of potentially sensitive information by expanding environmental variables and INI file values in URLs. When a document containing such links is opened, the information could be sent to a remote server. This issue arises from the application's handling of URLs, which could be crafted to exploit the variable expansion feature.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, such as environmental variables and INI file values, which could be exfiltrated to a remote server.
Users are advised to upgrade to LibreOffice 24.8.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.