Home
MEDIUM: 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 9.2.1
affected
Description
ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 9.2.1
References
github.com/...OFFICE/DocumentServer/blob/master/CHANGELOG.md
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.