id: CVE-2025-5301 info: name: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting author: theamanrawat severity: medium description: | ONLYOFFICE Docs (DocumentServer) <= 8.3.1 contains a reflected XSS caused by improper sanitization of crafted HTTP POST requests via the WOPI protocol, letting attackers inject malicious scripts reflected in HTML response, exploit requires crafted POST requests. impact: | Attackers can execute malicious scripts in users' browsers, potentially stealing session data or performing actions on behalf of users. remediation: | Update to a version later than 8.3.1. reference: - https://github.com/ONLYOFFICE/ - https://seclists.org/fulldisclosure/2025/Jun/18 - https://nvd.nist.gov/vuln/detail/CVE-2025-5301 - https://github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.md#832 - https://r.sec-consult.com/onlyoffice classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2025-5301 cwe-id: CWE-79 epss-score: 0.40668 epss-percentile: 0.98529 metadata: verified: false tags: cve,cve2025,onlyoffice,xss,vuln,seclists http: - raw: - | POST /hosting/wopi/word/edit?dchat=asdasd HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(content_type, "text/html")' - 'contains_all(body, "{\"dchat\":", "")' condition: and # digest: 4b0a00483046022100ebb8806c6713a9b3359b08722f50dfff0528e36ce622d6bcd53ccdab44a9b3d1022100e024195abf87ca4be625062a5b725327faf55c0f7465a91c673415c7bd2fa35d:922c64590222798bb761d5b6d8e72950