File Extension Handling Flaw in ONLYOFFICE DocumentServer
CVE-2021-25831
9.8CRITICAL
What is CVE-2021-25831?
A vulnerability exists in the ONLYOFFICE DocumentServer where improper handling of file extensions allows an attacker to convert a specially crafted PPTT file into PPTX format. By exploiting this flaw along with additional string handling weaknesses, a remote attacker could execute arbitrary code on the server. This exploitation poses a significant security risk for users relying on DocumentServer versions 4.0.0-9-v5.6.3.
