Record summary

CVE-2018-6871 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBLibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File DisclosureExploitDB exploitby Mikhail KlementevNot analyzed1 file
ExploitDB

PoC details

References

9