Local File Inclusion Vulnerability Affects Collabora Online
CVE-2024-30265

Currently unrated

Key Information:

Vendor
CVE Published:
3 April 2024

What is CVE-2024-30265?

Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilĂ  dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilĂ  dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilĂ  is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.

References

Timeline

  • Vulnerability published

.