Path Traversal Vulnerability in JSC R7 R7-Office Document Server
CVE-2025-10777
5.3MEDIUM
What is CVE-2025-10777?
A vulnerability in JSC R7 R7-Office Document Server allows for path traversal through manipulation of the 'cmd' argument in the /downloadas/ function. This vulnerability affects versions prior to 2025.3.1.923 and can be exploited remotely. Although the OpenOffice team was unable to reproduce the issue within their codebase, JSC confirmed that the vulnerability has been patched in the latest release. Users are strongly advised to upgrade to version 2025.3.1.923 to mitigate potential risks.
Affected Version(s)
R7-Office Document Server 20250820
R7-Office Document Server 2025.3.1.923