CVE-2020-12432
Last modified
CVE-2020-12432 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage. The attacker must first obtain an API access token, which can be accomplished if the attacker is able to upload a .docx or .odt file. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage. The attacker must first obtain an API access token, which can be accomplished if the attacker is able to upload a .docx or .odt file. The associated API endpoints for exploitation are /wopi/files and /wopi/getAccessToken.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Collaboraoffice | Collabora Online Development Edition | <= 4.2.2 |
References
- https://github.com/d7x/CVE-2020-12432Exploit, Third Party Advisory
- https://www.youtube.com/watch?v=_tkRnSr6yc0Exploit, Third Party Advisory
- https://github.com/d7x/CVE-2020-12432Exploit, Third Party Advisory
- https://www.youtube.com/watch?v=_tkRnSr6yc0Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-12432?
How severe is CVE-2020-12432?
How do I fix CVE-2020-12432?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-12426Mozilla developers and community members reported memory saf…8.8
- CVE-2020-12427The Western Digital WD Discovery application before 3.8.229 …8.8
- CVE-2020-12429Online Course Registration 2.0 has multiple SQL injections t…9.8
- CVE-2020-1243<p>A denial of service vulnerability exists when Microsoft H…7.8
- CVE-2020-12430An issue was discovered in qemuDomainGetStatsIOThread in qem…6.5
- CVE-2020-12431A Windows privilege change issue was discovered in Splashtop…6.6
- CVE-2020-12438An XSS vulnerability exists in the banners.php page of PHP-F…5.4
- CVE-2020-12439Grin before 3.1.0 allows attackers to adversely affect avail…5.3
- CVE-2020-1244A denial of service vulnerability exists when Connected User…7.1
- CVE-2020-12440Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-12441Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remot…9.8
- CVE-2020-12442Ivanti Avalanche 6.3 allows a SQL injection that is vaguely …9.8
Are you affected by CVE-2020-12432?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
