CVE-2021-43444
Description
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.
References
Third Party Advisory
ProductVendor Advisory
MitigationThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics