CVE-2020-12803


XForms submissions could overwrite local files

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.



We have discovered 2,325 live websites that are affected by CVE-2020-12803.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 0 before 6.4.4
Total Vulnerable Versions195
Vulnerable Domains2,325 live websites (68.93% of LibreOffice install base)



Details

  • Published - Jun 8, 2020
  • Updated - Dec 31, 2023




Countries

United States418 websites



Germany754 websites
France155 websites
Italy104 websites
GB79 websites
Czech Republic55 websites
Netherlands55 websites
Poland54 websites
Denmark52 websites
Russia45 websites

TLDs

.de597 websites
.com539 websites
.org167 websites
.net118 websites
.fr74 websites
.it65 websites
.dk46 websites
.nl42 websites
.co.uk41 websites
.info40 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2020-12803

Top websites that are affected by CVE-2020-12803. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.*****.bg Bulgaria***,***
**************.*******.de Germany***,***
*************.com Germany***,***
*****************.de Germany***,***
********.com United States***,***
******.cz Czech Republic***,***
***.****.br Brazil***,***
******.*******.de Germany***,***
*****************.cz Czech Republic***,***
*********.com Canada***,***
See full domain list