A directory traversal bug in ONLYOFFICE Document Server’s upload endpoint lets a remote, unauthenticated attacker write files outside the upload folder and potentially run code on the host.
A directory traversal bug in ONLYOFFICE Document Server’s upload endpoint lets a remote, unauthenticated attacker write files outside the upload folder and potentially run code on the host.