CVE-2023-2255
published 2023-05-25CVE-2023-2255: Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.24%
80.9th percentile
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 4.1.16 | 4.1.16 |
| apache_software_foundation | apache_openoffice | <= 4.1.15 | — |
| debian | debian_linux | — | — |
| debian | libreoffice | < libreoffice 4:7.4.5-3 (bookworm) | libreoffice 4:7.4.5-3 (bookworm) |
| libreoffice | libreoffice | >= 0 < 1:7.0.4-4+deb11u7 | 1:7.0.4-4+deb11u7 |
| libreoffice | libreoffice | >= 0 < 4:7.4.5-3 | 4:7.4.5-3 |
| libreoffice | libreoffice | >= 0 < 4:7.4.5-3 | 4:7.4.5-3 |
| libreoffice | libreoffice | >= 0 < 4:7.4.5-3 | 4:7.4.5-3 |
| libreoffice | libreoffice | >= 0 < 1:6.4.7-0ubuntu0.20.04.8 | 1:6.4.7-0ubuntu0.20.04.8 |
| libreoffice | libreoffice | >= 0 < 1:7.3.7-0ubuntu0.22.04.3 | 1:7.3.7-0ubuntu0.22.04.3 |
| libreoffice | libreoffice | >= 7.4.0 < 7.4.7 | 7.4.7 |
| libreoffice | libreoffice | >= 7.5.0 < 7.5.3 | 7.5.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibreOffice vulnerabilities
vendor_ubuntu·2023-06-07·CVSS 7.8
CVE-2023-2255 [HIGH] LibreOffice vulnerabilities
Title: LibreOffice vulnerabilities
Summary: Several security issues were fixed in LibreOffice.
It was discovered that LibreOffice did not properly validate the number of
parameters passed to the formula interpreter, leading to an array index
underflow attack. If a user were tricked into opening a specially crafted
spreadsheet file, an attacker could possibly use this issue to execute
arbitrary code. (CVE-2023-0950)
Amel Bouziane-Leblond discovered that LibreOffice did not prompt the user
before loading the host document inside an IFrame. If a user were tricked
into opening a specially crafted input file, an attacker could possibly use
this issue to cause information disclosure or execute arbitrary code.
(CVE-2023-2255)
Instructions: In general, a standard system update will make all th
Red Hat
libreoffice: Remote documents loaded without prompt via IFrame
vendor_redhat·2023-05-25·CVSS 5.3
CVE-2023-2255 [MEDIUM] libreoffice: Remote documents loaded without prompt via IFrame
libreoffice: Remote documents loaded without prompt via IFrame
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
A vulnerability was found in LibreOffice. Improper access control in the editor components of The Document Foundation in LibreOffice allows an attacker to craf
Debian
CVE-2023-2255: libreoffice - Improper access control in editor components of The Document Foundation LibreOff...
vendor_debian·2023·CVSS 5.3
CVE-2023-2255 [MEDIUM] CVE-2023-2255: libreoffice - Improper access control in editor components of The Document Foundation LibreOff...
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
Scope: local
bookworm: resolved (fixed in 4:7.4.5-3)
bullseye: resolved (fixed in 1:7.0.4-4+deb11u7)
forky: resolved (fixed in 4:7.4.5-3)
sid: resolved (fixed in 4:7.4.5-3)
trixie: resolved (fixed in 4:7.4.5-3)
GHSA
GHSA-7cr9-pfmp-g6m2: Apache OpenOffice documents can contain links
ghsa_unreviewed·2025-11-12·CVSS 5.3
CVE-2025-64401 [MEDIUM] CWE-862 GHSA-7cr9-pfmp-g6m2: Apache OpenOffice documents can contain links
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links
to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "floating frames" linked to external files would
load the contents of those frames without prompting the user for
permission to do so.
This issue affects Apache OpenOffice: through 4.1.15.
Users are recommended to upgrade to version 4.1.16, which fixes the issue.
The LibreOffice suite reported this issue as CVE-2023-2255
OSV
libreoffice vulnerabilities
osv·2023-06-07·CVSS 7.8
CVE-2023-0950 [HIGH] libreoffice vulnerabilities
libreoffice vulnerabilities
It was discovered that LibreOffice did not properly validate the number of
parameters passed to the formula interpreter, leading to an array index
underflow attack. If a user were tricked into opening a specially crafted
spreadsheet file, an attacker could possibly use this issue to execute
arbitrary code. (CVE-2023-0950)
Amel Bouziane-Leblond discovered that LibreOffice did not prompt the user
before loading the host document inside an IFrame. If a user were tricked
into opening a specially crafted input file, an attacker could possibly use
this issue to cause information disclosure or execute arbitrary code.
(CVE-2023-2255)
GHSA
GHSA-6pmq-j4m3-q2r8: Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external
ghsa_unreviewed·2023-05-25
CVE-2023-2255 [MEDIUM] GHSA-6pmq-j4m3-q2r8: Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
OSV
CVE-2023-2255: Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external
osv·2023-05-25·CVSS 5.3
CVE-2023-2255 [MEDIUM] CVE-2023-2255: Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
No detection rules found.
No public exploits indexed.
CTF
Mailing / README
ctf_writeups·CVSS 5.3
CVE-2024-21413 [MEDIUM] Mailing / README
# Mailing - HackTheBox - Writeup
Windows, 20 Base Points, Easy
## Machine
## TL;DR
To solve this machine, we start by using `nmap` to enumerate open services.
***User***: Found an LFI vulnerability in the `download.php` file. Download the `hMailServer.ini` file to obtain the password for the `Administrator` mailbox. Use `CVE-2024-21413` to leak the NTLM hash of the user `maya`.
***Root***: Discovered `LibreOffice`. Use `CVE-2023-2255` to add our user to the `Administrators` group. Retrieve the NTLM hash of the `localadmin` user using `crackmapexec`.
## Mailing Solution
### User
Let's begin by using `nmap` to scan the target machine:
```console
┌─[evyatar9@parrot]─[/hackthebox/Mailing]
└──╼ $ nmap -sV -sC -oA nmap/Mailing 10.10.11.14
Starting Nmap 7.93 ( https://nmap.org ) at 2
CTF
easy / README
ctf_writeups·CVSS 6.0
[MEDIUM] easy / README
---
layout: default
title: Easy Machines
parent: Machines
nav_order: 1
description: "120+ Easy HTB machine writeups with walkthroughs"
permalink: /machines/easy/
---
# HackTheBox Easy Machines - Comprehensive Reference
> Complete catalog of retired HTB Easy machines with OS, key vulnerability, attack path summary, and quality writeup links.
**Total: 100+ Easy Machines** | Updated: April 2026
---
## Quick Navigation
- [Classic / Legacy Machines (2017-2019)](#classic--legacy-machines-2017-2019)
- [2019-2020 Machines](#2019-2020-machines)
- [2021 Machines](#2021-machines)
- [2022 Machines](#2022-machines)
- [2023 Machines](#2023-machines)
- [2024 Machines (Season 4 & 5)](#2024-machines-season-4--5)
- [2025-2026 Machines (Season 6+)](#2025-2026-machines-season-6)
---
## Classic / Legac
https://lists.debian.org/debian-lts-announce/2023/08/msg00014.htmlhttps://security.gentoo.org/glsa/202311-15https://www.debian.org/security/2023/dsa-5415https://www.libreoffice.org/about-us/security/advisories/CVE-2023-2255https://lists.debian.org/debian-lts-announce/2023/08/msg00014.htmlhttps://security.gentoo.org/glsa/202311-15https://www.debian.org/security/2023/dsa-5415https://www.libreoffice.org/about-us/security/advisories/CVE-2023-2255
2023-05-25
Published