CVE-2023-46988: ONLYOFFICE Document Server

Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).

Affected products

  • ONLYOFFICE Document Server: from 7.4.0, before 8.0.1 (fixed in 8.0.1)

Published 2025-04-01. Last modified 2026-06-17.