CVE-2019-9850


Insufficient url validation allowing LibreLogo script execution

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from script event handers. However an insufficient url validation vulnerability in LibreOffice allowed malicious to bypass that protection and again trigger calling LibreLogo from script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.



We have discovered 2,159 live websites that are affected by CVE-2019-9850.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 0 before 6.2.6
Total Vulnerable Versions195
Vulnerable Domains2,159 live websites (64.01% of LibreOffice install base)



Details

  • Published - Aug 15, 2019
  • Updated - Oct 6, 2019

Credits

  • Thanks to alex (@insertscript) for reporting this issue




Countries

United States392 websites



Germany685 websites
France139 websites
Italy96 websites
GB71 websites
Poland54 websites
Czech Republic52 websites
Denmark51 websites
Netherlands50 websites
Russia42 websites

TLDs

.de545 websites
.com503 websites
.org155 websites
.net104 websites
.fr68 websites
.it60 websites
.dk45 websites
.pl40 websites
.nl38 websites
.co.uk37 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2019-9850

Top websites that are affected by CVE-2019-9850. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.*****.bg Bulgaria***,***
**************.*******.de Germany***,***
*****************.de Germany***,***
********.com United States***,***
******.cz Czech Republic***,***
***.****.br Brazil***,***
******.*******.de Germany***,***
*****************.cz Czech Republic***,***
************************.com United States***,***
**********.com United States***,***
See full domain list