Vulnerabilities > Onlyoffice > Document Server > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-09 | CVE-2023-50883 | Cross-site Scripting vulnerability in Onlyoffice Document Server ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. | 6.1 |
2022-04-08 | CVE-2022-24229 | Cross-site Scripting vulnerability in Onlyoffice Document Server A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor. | 6.1 |