CVE-2020-12432 (collabora_online_development_edition)
The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim’s browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or… Continue reading CVE-2020-12432 (collabora_online_development_edition)
