Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6186


Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.


Published

2023-12-11T12:15:07.713

Last Modified

2025-02-13T18:16:06.477

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.3 (HIGH)

Weaknesses
  • Type: Primary
    CWE-281

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application libreoffice libreoffice < 7.5.9 Yes
Application libreoffice libreoffice < 7.6.4 Yes
Operating System fedoraproject fedora 38 Yes
Operating System debian debian_linux 11.0 Yes
Operating System debian debian_linux 12.0 Yes

References