Vulnerabilities > Collaboraoffice > Collabora Online Development Edition > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-21 CVE-2020-12432 Cross-site Scripting vulnerability in Collaboraoffice Collabora Online Development Edition
The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage.
network
low complexity
collaboraoffice CWE-79
6.1