Vulnerability Description
ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446 and CVE-2023-50883.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Onlyoffice | Onlyoffice | < 8.1.0 |
Related Weaknesses (CWE)
References
- https://www.onlyoffice.com/Product
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-027.tExploitThird Party Advisory
- https://www.syss.de/pentest-blog/cross-site-scripting-schwachstelle-in-onlyofficThird Party Advisory
FAQ
What is CVE-2024-44085?
CVE-2024-44085 is a vulnerability with a CVSS score of 6.1 (MEDIUM). ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue...
How severe is CVE-2024-44085?
CVE-2024-44085 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-44085?
Check the references section above for vendor advisories and patch information. Affected products include: Onlyoffice Onlyoffice.