CVE-2023-30186

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
14/08/2023
Last modified:
21/08/2023

Description

A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:* 4.0.3 (including) 7.3.2 (including)