SQL Injection Vulnerability in ONLYOFFICE Document Server 5.5.0 via Websocket API

SQL Injection Vulnerability in ONLYOFFICE Document Server 5.5.0 via Websocket API

CVE-2020-11537 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.

Learn more about our Cis Benchmark Audit For Microsoft Office.