Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-6871. PoCs published by Mikhail Klementev.
AI-analyzed exploit summary This exploit leverages a vulnerability in LibreOffice's WEBSERVICE function to read local files and exfiltrate their contents via HTTP requests. The PoC demonstrates file disclosure by embedding malicious formulas in a spreadsheet document.
Description
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
Exploits (1)
This exploit leverages a vulnerability in LibreOffice's WEBSERVICE function to read local files and exfiltrate their contents via HTTP requests. The PoC demonstrates file disclosure by embedding malicious formulas in a spreadsheet document.
References (8)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H