Apache OpenOffice: Macro URL arbitrary script execution
CVE-2022-47502
7.8HIGH
What is CVE-2022-47502?
In Apache OpenOffice, documents can include links designed to invoke internal macros with arbitrary parameters. These links can be triggered either through user clicks or automatically by document events. For specific link activations in impacted versions, user confirmation is bypassed, creating a risk for unauthorized script execution without the user's consent.
Affected Version(s)
Apache OpenOffice 0 <= 4.1.13