CVE-2024-3044 — Product UI does not Warn User of Unsafe Actions in Document Foundation Libreoffice
Severity
6.5MEDIUMNVD
EPSS
2.4%
top 15.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14
Latest updateMay 28
Description
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LExploitability: 3.9 | Impact: 2.5
Affected Packages3 packages
Also affects: Debian Linux 10.0, Fedora 39
🔴Vulnerability Details
3GHSA▶
GHSA-3j7w-h2jh-289j: Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt w↗2024-05-14
OSV▶
CVE-2024-3044: Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt w↗2024-05-14