ZeroHour

CVE-2025-5301

large

Reflected XSS in ONLYOFFICE Docs (DocumentServer) 8.3.1 and earlier via WOPI

CVSS 3.1
6.1 medium
EPSS
46%p99
Published
()
Modified
AI analysis

ONLYOFFICE Docs (DocumentServer) version 8.3.1 and earlier contains a reflected cross-site scripting flaw (CWE-79) in how files are opened via the WOPI protocol. An attacker can send crafted HTTP POST requests whose injected script content is reflected unescaped into the server's HTML response, with CVSS indicating no privileges required but user interaction needed for execution. Successful exploitation runs attacker-controlled JavaScript in the context of the ONLYOFFICE Docs web interface (scope-changing per CVSS S:C), enabling actions such as stealing session tokens or acting as the logged-in user, with low confidentiality and integrity impact. Any organization running a self-hosted ONLYOFFICE Docs/DocumentServer instance at 8.3.1 or older with WOPI enabled - the protocol typically used when integrating Docs with third-party file-sharing and collaboration platforms - is affected. No public PoC, CISA KEV listing, or confirmed in-the-wild exploitation is known, but EPSS is 46.1% (99th percentile), indicating an elevated probability of exploitation within the next 30 days.

What to do: Upgrade ONLYOFFICE Docs/DocumentServer to a release newer than 8.3.1 that resolves this issue, prioritizing internet-exposed and multi-tenant deployments. Until patched, restrict network access to the DocumentServer to trusted WOPI peers and review WOPI endpoint logs for anomalous crafted POST requests; monitor advisories for a disclosed fixed version and any emerging PoC given the high EPSS score.

Affected
ONLYOFFICE Docs (DocumentServer)All versions equal to or below 8.3.1
Estimated exposure
largelikely tens of thousands of self-hosted instances (order of 100k+ end users) — Estimate based on deployment patterns: ONLYOFFICE Docs is a widely deployed self-hosted office suite commonly integrated via WOPI with file-sharing platforms, and every release through 8.3.1 was affected at disclosure, so exposure spans…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.