CVE-2020-12802


remote graphics contained in docx format retrieved in 'stealth mode'

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.



We have discovered 2,325 live websites that are affected by CVE-2020-12802.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 0 before 6.4.4
Total Vulnerable Versions195
Vulnerable Domains2,325 live websites (68.93% of LibreOffice install base)


Common Weakness Enumeration


CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jun 8, 2020
  • Updated - Dec 31, 2023





Countries

United States418 websites



Germany754 websites
France155 websites
Italy104 websites
GB79 websites
Czech Republic55 websites
Netherlands55 websites
Poland54 websites
Denmark52 websites
Russia45 websites

TLDs

.de597 websites
.com539 websites
.org167 websites
.net118 websites
.fr74 websites
.it65 websites
.dk46 websites
.nl42 websites
.co.uk41 websites
.info40 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2020-12802

Top websites that are affected by CVE-2020-12802. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.*****.bg Bulgaria***,***
**************.*******.de Germany***,***
*************.com Germany***,***
*****************.de Germany***,***
********.com United States***,***
******.cz Czech Republic***,***
***.****.br Brazil***,***
******.*******.de Germany***,***
*****************.cz Czech Republic***,***
*********.com Canada***,***
See full domain list