CVE-2020-11537
EUVD-2020-388915.04.2020, 15:15
A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| onlyoffice | document_server | 5.5.0 |
𝑥
= Vulnerable software versions