CVE-2023-30187

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
14/08/2023
Last modified:
21/08/2023

Description

An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:* 4.0.3 (including) 7.3.2 (including)