CVE-2020-12803Improper Input Validation in Document Foundation Libreoffice

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 35.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 8
Latest updateOct 20

Description

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5the_document_foundation/libreofficeunspecified6.4.4
Debianlibreoffice/libreoffice< 1:6.4.4-1+3
NVDopensuse/leap15.1

Also affects: Fedora 31

🔴Vulnerability Details

3
GHSA
GHSA-gxcj-pjgw-2hvw: ODF documents can contain forms to be filled out by the user2022-05-24
OSV
CVE-2020-12803: ODF documents can contain forms to be filled out by the user2020-06-08
CVEList
XForms submissions could overwrite local files2020-06-08

📋Vendor Advisories

3
Ubuntu
LibreOffice vulnerabilities2022-10-20
Red Hat
libreoffice: forms allowed to be submitted to any URI could result in local file overwrite2020-06-08
Debian
CVE-2020-12803: libreoffice - ODF documents can contain forms to be filled out by the user. Similar to HTML fo...2020

💬Community

2
Bugzilla
CVE-2020-12803 libreoffice: forms allowed to be submitted to any URI could result in local file overwrite [fedora-all]2020-06-18
Bugzilla
CVE-2020-12803 libreoffice: forms allowed to be submitted to any URI could result in local file overwrite2020-06-18
CVE-2020-12803 — Improper Input Validation | cvebase