Improper Input Validation in ONLYOFFICE Product
CVE-2021-43448

5.3MEDIUM

Key Information:

Vendor

Onlyoffice

Status
Vendor
CVE Published:
23 January 2023

What is CVE-2021-43448?

ONLYOFFICE Document Server is susceptible to improper input validation which enables attackers to impersonate users by spoofing their names in documents. This vulnerability arises when an attacker knows the document ID, allowing them to manipulate user interactions within the platform. Such flaws may undermine user trust and data integrity, highlighting the importance of robust input validation mechanisms.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-43448 : Improper Input Validation in ONLYOFFICE Product