Authentication Bypass Vulnerability in ONLYOFFICE Document Editor
CVE-2021-43447

7.5HIGH

Key Information:

Vendor

Onlyoffice

Status
Vendor
CVE Published:
23 January 2023

What is CVE-2021-43447?

The ONLYOFFICE Document Editor is susceptible to an authentication bypass flaw that allows unauthorized individuals to edit documents without requiring proper authentication. This vulnerability poses a significant risk as it could enable attackers to manipulate sensitive documents, leading to potential data breaches and loss of data integrity. Users and administrators must prioritize the application of security patches and implement robust access control measures to mitigate this risk.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-43447 : Authentication Bypass Vulnerability in ONLYOFFICE Document Editor