CVE-2025-5301 Details
Description
ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.
A reflected cross-site scripting vulnerability has been identified in ONLYOFFICE Docs (DocumentServer) versions through 8.3.1. This issue arises when files are opened via the WOPI protocol, allowing attackers to inject malicious scripts through crafted HTTP POST requests. The injected scripts are then reflected in the server's HTML response.
Users are advised to upgrade to ONLYOFFICE Docs version 8.3.2 or higher.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2025CISA-ADP
Assessed Jun 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec-consult.com/vulnerability-lab/advisory/reflected-cross-site-scripting-in-onlyoffice-docs-documentserver/ | CISA-ADP | |
| https://github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.md#832 | SEC Consult Vulnerability Lab | Vendor |
| https://r.sec-consult.com/onlyoffice | SEC Consult Vulnerability Lab | AdvisoryExploitRemedy |
| http://seclists.org/fulldisclosure/2025/Jun/18 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| ONLYOFFICE Docs | <= 8.3.1 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2025 | CVE Modified | CVE |
| Jun 12, 2025 | CVE Modified | CISA-ADP |
| Jun 12, 2025 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion