Improper Input Validation in ONLYOFFICE Product
CVE-2021-43448
5.3MEDIUM
What is CVE-2021-43448?
ONLYOFFICE Document Server is susceptible to improper input validation which enables attackers to impersonate users by spoofing their names in documents. This vulnerability arises when an attacker knows the document ID, allowing them to manipulate user interactions within the platform. Such flaws may undermine user trust and data integrity, highlighting the importance of robust input validation mechanisms.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
