ZeroHour

CVE-2020-11537

CVSS 3.1
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.

Vendors
onlyoffice
Products
document server
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.