Cross Site Scripting Vulnerability in OnlyOffice by Ascensio System SIA
CVE-2025-10254
Key Information:
- Vendor
Ascensio System Sia
- Status
- Vendor
- CVE Published:
- 11 September 2025
Badges
What is CVE-2025-10254?
A vulnerability in OnlyOffice, produced by Ascensio System SIA, allows for cross site scripting via the SVG Image Handler component. Specifically, this affects the file processing of /Products/Projects/Messages.aspx. An attacker can exploit this security flaw remotely, leading to potential unauthorized access and manipulation. The vendor has acknowledged the issue and is actively working on a patch to resolve these vulnerabilities in a future update.
Affected Version(s)
OnlyOffice 12.0
OnlyOffice 12.1
OnlyOffice 12.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
