CVE-2023-46988
Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).
- Affected products
- Onlyoffice Document Server
- Onlyoffice Document Server
- < 8.0.1
- Fix
- Available
- CVSS 3.1
- 6.7 MEDIUM
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2025-04-01
CVE-2023-46988 at NVD
1 known exploit for CVE-2023-46988
Proof-of-concept code and exploit modules indexed by Sploitus