Description
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.
References (5)
Scores
CVSS v3
6.3
EPSS
0.0132
EPSS Percentile
80.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Details
CWE
CWE-88
CWE-20
Status
published
Products (4)
debian/debian_linux
11.0
fedoraproject/fedora
35
libreoffice/libreoffice
7.4.0
libreoffice/libreoffice
7.3.0 - 7.3.6
Published
Oct 11, 2022
Tracked Since
Feb 18, 2026