
2️⃣ CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution This researcher discovered an unauthenticated WebSocket in ONLYOFFICE that allowed downloading documents, injecting macros, and achieving SSRF. The default JWT key was literally "secret"! 👀 https://www.lrqa.com/en/cyber-labs/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/
Post summary
The post announces that ONLYOFFICE’s default WebSocket is vulnerable to unauthenticated RCE via SSRF and document injection, but offers no PoC or patch information.
