CVE-2023-2255
Remote documents loaded without prompt via IFrame
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
A vulnerability was found in LibreOffice. Improper access control in the editor components of The Document Foundation in LibreOffice allows an attacker to craft a document that causes external links to load without a prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, they would load the contents of those frames without prompting the user for permission. This action was inconsistent with the treatment of other linked content in LibreOffice.
It was discovered that LibreOffice did not properly validate the number of parameters passed to the formula interpreter, leading to an array index underflow attack. If a user were tricked into opening a specially crafted spreadsheet file, an attacker could possibly use this issue to execute arbitrary code. Amel Bouziane-Leblond discovered that LibreOffice did not prompt the user before loading the host document inside an IFrame. If a user were tricked into opening a specially crafted input file, an attacker could possibly use this issue to cause information disclosure or execute arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-04-24 CVE Reserved
- 2023-05-25 CVE Published
- 2023-07-10 First Exploit
- 2024-08-02 CVE Updated
- 2025-05-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/08/msg00014.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://github.com/elweth-sec/CVE-2023-2255 | 2023-07-10 | |
https://github.com/SaintMichae64/CVE-2023-2255 | 2024-05-04 | |
https://github.com/G4sp4rCS/CVE-2023-2255 | 2025-04-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202311-15 | 2023-11-26 | |
https://www.debian.org/security/2023/dsa-5415 | 2023-11-26 | |
https://www.libreoffice.org/about-us/security/advisories/CVE-2023-2255 | 2023-11-26 | |
https://access.redhat.com/security/cve/CVE-2023-2255 | 2023-11-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2210185 | 2023-11-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libreoffice Search vendor "Libreoffice" | Libreoffice Search vendor "Libreoffice" for product "Libreoffice" | >= 7.4.0 < 7.4.7 Search vendor "Libreoffice" for product "Libreoffice" and version " >= 7.4.0 < 7.4.7" | - |
Affected
| ||||||
Libreoffice Search vendor "Libreoffice" | Libreoffice Search vendor "Libreoffice" for product "Libreoffice" | >= 7.5.0 < 7.5.3 Search vendor "Libreoffice" for product "Libreoffice" and version " >= 7.5.0 < 7.5.3" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
|