CVE-2023-46988
CVE-2023-46988 is a medium-severity vulnerability in Onlyoffice Document Server with a CVSS 3.x base score of 6.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 6.7)
- EPSS exploit prediction: 1% (42nd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2023-51146
- Weakness: CWE-22
- Affected product: Onlyoffice Document Server
- Published:
- Last modified:
Description
Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).
Frequently asked questions
- What is CVE-2023-46988?
- Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).
- How severe is CVE-2023-46988?
- CVE-2023-46988 has a CVSS 3.x base score of 6.7, rated medium severity. It is exploitable over local access with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2023-46988 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (42nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-46988?
- CVE-2023-46988 affects Onlyoffice Document Server. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-46988?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2023-46988 have an EU (EUVD) identifier?
- Yes. CVE-2023-46988 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2023-51146.
- When was CVE-2023-46988 published?
- CVE-2023-46988 was published on 2025-04-01 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*
More vulnerabilities in Onlyoffice Document Server
- CVE-2023-30187 — Critical (CVSS 9.8): An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers…
- CVE-2023-30186 — Critical (CVSS 9.8): A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run…
- CVE-2022-29777 — Critical (CVSS 9.8): Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via…
- CVE-2022-29776 — Critical (CVSS 9.8): Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via…
- CVE-2021-25833 — Critical (CVSS 9.8): A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file…
- CVE-2021-25832 — Critical (CVSS 9.8): A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE…
All CVEs affecting Onlyoffice Document Server →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-55393 — Critical (CVSS 10.0): Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9…
- CVE-2026-97163 — Critical (CVSS 10.0): Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
- CVE-2026-80155 — Critical (CVSS 10.0): Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1,…
- CVE-2026-70200 — Critical (CVSS 10.0): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an…
- CVE-2026-85706 — Critical (CVSS 10.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9,…
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.