GHSA-r5fg-8fjv-3w9h
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 17, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.