#VU77534 External control of file name or path in LibreOffice - CVE-2023-1183
Published: June 20, 2023 / Updated: December 29, 2023
LibreOffice
LibreOffice
Description
The vulnerability allows a remote attacker to write files to an arbitrary location on the system.
The vulnerability exists due to improper input validation when processing files within hsqldb. A remote attacker can trick the victim to open a specially crafted odb file that contains a "database/script" file with a SCRIPT command and write contents of that file to an arbitrary location on the system.
Successful exploitation of the vulnerability can lead to full system compromise.