CVE-2020-12803

XForms submissions could overwrite local files

Description

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

Category

6.5
CVSS
Severity: Medium
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.46%
Vendor Advisory fedoraproject.org Vendor Advisory opensuse.org Vendor Advisory opensuse.org Vendor Advisory libreoffice.org
Affected: The Document Foundation LibreOffice
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2020-12803?
CVE-2020-12803 has been scored as a medium severity vulnerability.
How to fix CVE-2020-12803?
To fix CVE-2020-12803, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2020-12803 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2020-12803 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2020-12803?
CVE-2020-12803 affects The Document Foundation LibreOffice.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.