漏洞描述 Ascensio System ONLYOFFICE是拉脱维亚Ascensio System公司的一款办公软件。 Ascensio System ONLYOFFICE DocumentServer 4.0.3至7.3.2版本存在资源管理错误漏洞,该漏洞源于存在释放后重用漏洞。攻击者可利用该漏洞通过设计JavaScript文件执行任意代码。
相关漏洞推荐 金慧综合管理信息系统SystemName参数存在SQL注入漏洞 Code-Projects Refugee Food Management System SQL注入漏洞 CampCodes Supplier Management System SQL注入漏洞 Code-Projects College Notes Uploading System SQL注入漏洞 itsourcecode Online Frozen Foods Ordering System SQL注入漏洞 (CVE-2025-15011)Simple Stock System 1.0 logout.php SQL注入漏洞 POC CVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting POC CVE-2021-4462: Employee Records System 1.0 - Unauthenticated File Upload RCE POC CVE-2023-38875: PHP Login System 2.0.1 - Cross-Site Scripting 中成科信票务管理系统 /SystemManager/Api/TicketManager.ashx SQL 注入漏洞 泛微e-office /E-mobile/App/System/UserSelect/dept.php 未授权访问漏洞 School Fees Payment System /student.php SQL 注入漏洞(CVE-2025-6403) (CVE-2021-4462)Employee Records System 1.0任意文件上传漏洞