CVE Database
/

CVE-2022-47412

Back to search

CVE-2022-47412

Published: Feb 7, 2023

Modified: Mar 25, 2025

PUBLISHED

Description

Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition.

VendorProductVersions

ONLYOFFICE

Workspace

affected
0 - <= 12.1.0.1760

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now