CVE-2021-43446

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
23/01/2023
Last modified:
02/04/2025

Description

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:onlyoffice:server:*:*:*:*:*:*:*:* 7.0.0.49 (including)