CVE-2020-11537
A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries
A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.
CRITICAL · CVSS 9.8
EPSS 0.00398
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0