CVE Vulnerabilities

CVE-2021-40864

Published: Sep 10, 2021 | Modified: Sep 24, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.

Affected Software

Name Vendor Start Version End Version
Google_translate Onlyoffice 6.1.0 (including) 6.3.0.72 (excluding)

References