Improper access control in LibreOffice - CVE-2019-9854
Published: September 10, 2019
LibreOffice
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to unsafe URL assembly flaw in allowed script location check. A remote authenticated attacker can execute script in arbitrary locations on the filesystem by employing a URL encoding attack to defeat the path verification step.