9.8
CVSSv3

CVE-2021-3199

Published: 26/01/2021 Updated: 15/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server prior to 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

onlyoffice document server

Github Repositories

🕳️ Proof of Concept exploits and their descriptions for various products

Proofs of Concepts, Exploits, CVE ConnMan ConnMan is a command-line network manager designed for use with embedded devices and fast resolve times CVE ID Score Description CVE-2023-28488 ? Integer underflow and subsequent stack buffer overflow gdhcp in ConnMan through 141 could be used by network-adjacent attackers to cause a denial of service, terminating the connman