CVE-2025-5301
largeReflected XSS in ONLYOFFICE Docs (DocumentServer) 8.3.1 and earlier via WOPI
ONLYOFFICE Docs (DocumentServer) version 8.3.1 and earlier contains a reflected cross-site scripting flaw (CWE-79) in how files are opened via the WOPI protocol. An attacker can send crafted HTTP POST requests whose injected script content is reflected unescaped into the server's HTML response, with CVSS indicating no privileges required but user interaction needed for execution. Successful exploitation runs attacker-controlled JavaScript in the context of the ONLYOFFICE Docs web interface (scope-changing per CVSS S:C), enabling actions such as stealing session tokens or acting as the logged-in user, with low confidentiality and integrity impact. Any organization running a self-hosted ONLYOFFICE Docs/DocumentServer instance at 8.3.1 or older with WOPI enabled - the protocol typically used when integrating Docs with third-party file-sharing and collaboration platforms - is affected. No public PoC, CISA KEV listing, or confirmed in-the-wild exploitation is known, but EPSS is 46.1% (99th percentile), indicating an elevated probability of exploitation within the next 30 days.
What to do: Upgrade ONLYOFFICE Docs/DocumentServer to a release newer than 8.3.1 that resolves this issue, prioritizing internet-exposed and multi-tenant deployments. Until patched, restrict network access to the DocumentServer to trusted WOPI peers and review WOPI endpoint logs for anomalous crafted POST requests; monitor advisories for a disclosed fixed version and any emerging PoC given the high EPSS score.
| ONLYOFFICE Docs (DocumentServer) | All versions equal to or below 8.3.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.