CyberRota Analysis
AI-GeneratedAn unauthenticated remote attacker can exploit a vulnerability in OnlyOffice/Document Editing within Office products to perform path-traversal writes, allowing them to execute commands with the privileges of the zimbra user. This critical vulnerability poses a significant risk to organizations using these products, particularly those that utilize public Briefcase documents. Organizations should prioritize patching this vulnerability to mitigate potential unauthorized access and command execution risks.
Original NVD Description
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.