CVE-2021-32745
Reflected Cross-Site-Scripting vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online prior to version 6.4.9-5. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and execute scripts inside the context of the Collabora Online iframe. This would give access to a small set of user settings stored in the browser, as well as the session's authentication token which was also passed in at iframe creation time. The issue is patched in Collabora Online 6.4.9-5. Collabora Online 4.2 is not affected.
Collabora Online es una suite de office colaborativa online. Se ha encontrado una vulnerabilidad de tipo XSS reflejado en Collabora Online anterior a versión 6.4.9-5. Un atacante podría inyectar HTML sin escapar en una variable ya que crearon el iframe de Collabora Online, y ejecutar scripts dentro del contexto del iframe de Collabora Online. Esto daría acceso a un pequeño ajuste de configuraciones de usuario almacenadas en el navegador, así como al token de autenticación de la sesión que también se pasaba en el momento de la creación del iframe. El problema está parcheado en Collabora Online 6.4.9-5. Collabora Online 4.2 no está afectado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-12 CVE Reserved
- 2021-07-21 CVE Published
- 2024-04-05 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/CollaboraOnline/online/security/advisories/GHSA-w536-654v-cjj9 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Collabora Search vendor "Collabora" | Online Search vendor "Collabora" for product "Online" | > 4.2 < 6.4.9-5 Search vendor "Collabora" for product "Online" and version " > 4.2 < 6.4.9-5" | - |
Affected
|