Loading HuntDB...

GHSA-r5fg-8fjv-3w9h

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.

Related CVEs

Key Information

GHSA ID
GHSA-r5fg-8fjv-3w9h
Published
June 12, 2025 9:30 AM
Last Modified
June 12, 2025 3:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 17, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.