Home
MEDIUM: 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 9.2.1
affected
Description
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 9.2.1
References
github.com/...OFFICE/DocumentServer/blob/master/CHANGELOG.md
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.