CVE-2021-25833
CRITICALONLYOFFICE DocumentServer 4.2.0.71-5.6.0.21 - Remote Code Execution via File Extension Handling Issue
Title source: llmDescription
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.
References (6)
Core 6
Core References
Product, Vendor Advisory x_refsource_misc
https://github.com/ONLYOFFICE/DocumentServer
Product x_refsource_misc
https://github.com/ONLYOFFICE/server
Third Party Advisory x_refsource_misc
https://github.com/ONLYOFFICE/server/blob/v5.6.0.21/DocService/sources/converterservice.js#L200
Third Party Advisory x_refsource_misc
https://github.com/ONLYOFFICE/server/blob/v5.6.0.21/FileConverter/sources/converter.js#L593
Third Party Advisory x_refsource_misc
https://github.com/ONLYOFFICE/server/blob/v5.6.0.21/FileConverter/sources/converter.js#L283
Exploit, Third Party Advisory x_refsource_misc
https://github.com/merrychap/poc_exploits/tree/master/ONLYOFFICE/CVE-2021-25833
Scores
CVSS v3
9.8
EPSS
0.4353
EPSS Percentile
98.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (1)
onlyoffice/document_server
4.2.0.71 - 5.6.0.21
Published
Mar 01, 2021
Tracked Since
Feb 18, 2026