What the vulnerability does
01Description
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.
Explanation of Vulnerability in Simple Terms
Woffice Core versions up to 5.4.8 contain a vulnerability that allows an attacker to read sensitive information, modify data, or disrupt service by tricking a user into visiting a malicious link. The vulnerability affects multiple security functions and requires user interaction to exploit. Site administrators should update to a version newer than 5.4.8 as soon as possible.
What an attacker can do
Read sensitive data, modify site content, or cause service disruption by tricking a user into clicking a malicious link.
Potential impact on your site
Users' data could be exposed, site content could be altered, or service could be disrupted if they click attacker-controlled links.
Conditions required to exploit
The attacker must trick a user into visiting a malicious link or page (user interaction required). No authentication needed.
Key dates
External resources