It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HLibreoffice
APPLibreoffice< 6.0.76.1.0 – 6.1.3 (excl.)
Related vulnerabilities
LibreOffice LibreOfficeKit — wyłączona weryfikacja certyfikatów TLS
LibreOffice (Windows): obejście zabezpieczeń LibreLogo przez ścieżki 8.3
LibreOffice LibreLogo — ominięcie zabezpieczeń i wykonanie kodu Python z dokumentu
LibreOffice: bypass ochrony CVE-2019-9848 przez niewystarczającą walidację URL
LibreOffice: wykonanie kodu przez LibreLogo w obsłudze zdarzeń dokumentu