Skip to content

CVE-2024-29182 Stored Cross-Site-Scripting vulnerability via tooltip

High
caolanm published GHSA-9gmw-5q2c-4398 Apr 2, 2024

Package

coolwsd (Collabora Online)

Affected versions

< 23.05.10.1

Patched versions

23.05.10.1

Description

Impact

A stored XSS vulnerability was found in Collabora Online. An attacker could create a document with an XSS payload in document text referenced by field which, if hovered over to produce a tooltip, could be executed by the user's browser.

Patches

Users should upgrade to Collabora Online 23.05.10.1 or higher; Earlier series of Collabora Online, 22.04, 21.11, etc are unaffected.

Credits

Thanks to David Miller from cyllective AG (https://cyllective.com/) for reporting this flaw.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2024-29182

Weaknesses

Credits