← Back to CVE List

CVE-2021-3199

Published: 2021-01-26T18:16Z
Last Modified: 2024-11-21T06:21Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt