CVE-2018-6871
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
- Libreoffice
- < 5.4.5, 6.0.0
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 22.8% (97th percentile)
- NVD status
- Modified
- Published
- 2018-02-09
CVE-2018-6871 at NVD
4 known exploits for CVE-2018-6871
Proof-of-concept code and exploit modules indexed by Sploitus