ZeroHour

CVE-2020-13451

PoC
CVSS 3.1
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.

Vendors
thecodingmachine
Products
gotenberg
Weakness
CWE-459
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.