CVE-2023-6186

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/12/2023
Last modified:
13/02/2025

Description

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.<br /> <br /> In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* 7.5.0 (including) 7.5.9 (excluding)
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* 7.6.0 (including) 7.6.4 (excluding)
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*