Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://github.com/firsov/onlyoffice | exploit |
https://github.com/ONLYOFFICE/CommunityServer/blob/master/CHANGELOG.md#version-1252 | release notes |
https://github.com/firsov/onlyoffice/blob/main/CVE-2023-34939-PoC.md | third party advisory exploit |