可构造的 URL 能够扩展环境变量或 INI 文件中的值,因此当用户打开包含此类链接的文档时,敏感信息可能会被泄露到远程服务器。为修复 CVE-2024-12426 而添加的检查并未覆盖文档提供 URL 的所有位置。XForms 实例数据以及 Calc 的 CSV 和 SQL 数据提供程序仍然会触发该值扩展。在修复版本中,当 URL 来自文档时,这些位置会拒绝使用内部方案的 URL。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Document Foundation | LibreOffice | 26.2 ~ < 26.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63277 | 8.5 HIGH | RCE via calcext:data-mappings, sql provider and jdbc connector |
| CVE-2026-63266 | 6.8 MEDIUM | Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functiona |
| CVE-2026-63269 | 6.7 MEDIUM | LFI and GET SSRF via GStreamer and HLS playlists |
| CVE-2026-63267 | 6.7 MEDIUM | LFI and GET SSRF via calcext:data-mappings and csv provider |
| CVE-2026-63268 | 6.7 MEDIUM | LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href |
No comments yet