V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-2255
AST
MediumConfirmedExploit available

Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would caus…

CVSS
5.3
Medium
EPSS
0.02
p80
Published
2023-01-01
Updated
2023-01-01
Description

Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.

Tags · CWE
Pre-auth
CWE-264
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.022 · p80
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2023-2255
github-poc · https://github.com/G4sp4rCS/CVE-2023-2255
Enterprise
Affected products
ProductVendorStatus
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
debian_linux*Tracked
libreoffice*Tracked
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities