MEDIUM🇵🇱 Wersja polska

CVE-2024-45045

CVSS 6.3v3.1pub. 2024-08-29upd. 2024-09-03

Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) device variants of Collabora Online it was possible to inject JavaScript via url encoded values in links contained in documents. Since the Android JavaScript interface allows access to internal functions, the likelihood that the app could be compromised via this vulnerability is considered high. Non-mobile variants are not affected. Mobile variants should update to the latest version provided by the platform appstore. There are no known workarounds for this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
  • Collabora Online

    APP
    Collabora
    < 24.04.6.2
  • Google Android

    OS
    Google
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-16010CRITICAL9.6⚠ KEVPL ✓same product

Heap buffer overflow w Google Chrome na Android — sandbox escape

CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓same product

Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku

CVE-2026-78937CRITICAL9.6same product

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...

CVE-2026-79129CRITICAL9.6same product

Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...

CVE-2026-79152CRITICAL9.8same product

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...