Apache OpenOffice: Macro URL arbitrary script execution
CVE-2022-47502

7.8HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
24 March 2023

Summary

In Apache OpenOffice, documents can include links designed to invoke internal macros with arbitrary parameters. These links can be triggered either through user clicks or automatically by document events. For specific link activations in impacted versions, user confirmation is bypassed, creating a risk for unauthorized script execution without the user's consent.

Affected Version(s)

Apache OpenOffice 0 <= 4.1.13

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Altin Thartori (tin-z)
Joachim Mammele
.