Apache OpenOffice: Macro URL arbitrary script execution
CVE-2022-47502
7.8HIGH
Summary
In Apache OpenOffice, documents can include links designed to invoke internal macros with arbitrary parameters. These links can be triggered either through user clicks or automatically by document events. For specific link activations in impacted versions, user confirmation is bypassed, creating a risk for unauthorized script execution without the user's consent.
Affected Version(s)
Apache OpenOffice 0 <= 4.1.13
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Altin Thartori (tin-z)
Joachim Mammele