CVE Database
/

CVE-2023-47804

Back to search

CVE-2023-47804

Published: Dec 29, 2023

Modified: Feb 13, 2025

PUBLISHED

Description

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution. This is a corner case of CVE-2022-47502.

VendorProductVersions

Apache Software Foundation

Apache OpenOffice

affected
0 - <= 4.1.14

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now