Link targets allow arbitrary script execution
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.3epss 0.8%
probabilidad de explotación
0.8%top 48% de las CVE
explotación observada
noninguna fuente lo reporta
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.
In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
Productos afectados
The Document Foundation · LibreOfficeReferencias
https://lists.debian.org/debian-lts-announce/2023/12/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QB7UB6CTWQUDOE657OVVRSDYUY3IPBJG/https://www.debian.org/security/2023/dsa-5574https://www.libreoffice.org/about-us/security/advisories/cve-2023-6186