SQL Injection Vulnerability in ONLYOFFICE Document Server 5.5.0 via Websocket API
CVE-2020-11537 · CRITICAL Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.
Learn more about our Cis Benchmark Audit For Microsoft Office.