MEDIUM
The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage
Published Jul 21, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.87%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.