CVE-2021-25631

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-05-03 12:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-25631

Mitre link : CVE-2021-25631

CVE.ORG link : CVE-2021-25631


JSON object : View

Products Affected

libreoffice

  • libreoffice
CWE
NVD-CWE-Other CWE-184

Incomplete List of Disallowed Inputs