Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ONLYOFFICE 输入验证错误漏洞
Vulnerability Description
Ascensio System ONLYOFFICE是拉脱维亚Ascensio System公司的一款办公软件。 ONLYOFFICE 2021-11-08 之前的所有版本存在安全漏洞,该漏洞源于易受不当输入验证的影响。如果文档 ID 已知,则缺少输入验证可能允许攻击者伪造与文档交互的用户的姓名。
CVSS Information
N/A
Vulnerability Type
N/A