Remote Code Execution Vulnerability in ONLYOFFICE Document Server
CVE-2020-11534
9.8CRITICAL
What is CVE-2020-11534?
A vulnerability has been identified in ONLYOFFICE Document Server version 5.5.0 that allows attackers to exploit the NSFileDownloader function. This exploit occurs when a maliciously crafted .docx file is processed, permitting the execution of arbitrary commands on the server. Attackers can leverage this flaw to pass parameters to binaries like curl or wget, facilitating unauthorized remote code execution, thereby posing a significant risk to server integrity.
