CVE-2021-3199

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
26/01/2021
Last modified:
15/04/2022

Description

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:* 5.6.3 (excluding)