CVE-2025-5301
Last modified
CVE-2025-5301 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.. EPSS estimates a 34.86% chance of exploitation in the next 30 days.
Description
ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-5301?
How severe is CVE-2025-5301?
How do I fix CVE-2025-5301?
Are you affected by CVE-2025-5301?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
