Security Advisory
CVE-2021-43449
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and serve arbitrary URLs as a document.