CVE-2023-30186
published 2023-08-14CVE-2023-30186: A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.32%
82.7th percentile
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| onlyoffice | document_server | 4.0.3 – 7.3.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ONLYOFFICE Document Server up to 7.3.2 JavaScript File use after free (EUVD-2023-34611)
vuldb·2026-07-10·CVSS 9.8
CVE-2023-30186 [CRITICAL] ONLYOFFICE Document Server up to 7.3.2 JavaScript File use after free (EUVD-2023-34611)
A vulnerability described as critical has been identified in ONLYOFFICE Document Server up to 7.3.2. This affects an unknown part of the component JavaScript File Handler. Such manipulation leads to use after free.
This vulnerability is traded as CVE-2023-30186. The attack may be launched remotely. There is no exploit available.
A patch should be applied to remediate this issue.
GHSA
GHSA-m5p8-2r8q-qjjh: A use after free issue discovered in ONLYOFFICE DocumentServer 4
ghsa_unreviewed·2023-08-14
CVE-2023-30186 [CRITICAL] CWE-416 GHSA-m5p8-2r8q-qjjh: A use after free issue discovered in ONLYOFFICE DocumentServer 4
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gist.github.com/merrychap/25eba8c4dd97c9e545edad1b8f0eadc2https://github.com/ONLYOFFICE/DocumentServerhttps://github.com/ONLYOFFICE/core/blob/8ca40a44ce47a86168327a46db91253cf6bb205d/DesktopEditor/doctrenderer/https://github.com/ONLYOFFICE/core/blob/8ca40a44ce47a86168327a46db91253cf6bb205d/DesktopEditor/doctrenderer/embed/NativeControlEmbed.cpp#L110https://github.com/ONLYOFFICE/core/commit/2b6ad83b36afd9845085b536969d366d1d61150ahttps://gist.github.com/merrychap/25eba8c4dd97c9e545edad1b8f0eadc2https://github.com/ONLYOFFICE/DocumentServerhttps://github.com/ONLYOFFICE/core/blob/8ca40a44ce47a86168327a46db91253cf6bb205d/DesktopEditor/doctrenderer/https://github.com/ONLYOFFICE/core/blob/8ca40a44ce47a86168327a46db91253cf6bb205d/DesktopEditor/doctrenderer/embed/NativeControlEmbed.cpp#L110https://github.com/ONLYOFFICE/core/commit/2b6ad83b36afd9845085b536969d366d1d61150a
2023-08-14
Published