Vulnerabilities > Collaboraoffice > Collabora Online Development Edition
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-07-21 | CVE-2020-12432 | Cross-site Scripting vulnerability in Collaboraoffice Collabora Online Development Edition The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage. | 6.1 |