Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
2024-05-14T21:15:12.627
2025-12-10T19:10:17.363
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | libreoffice | libreoffice | < 7.6.7.1 | Yes |
| Application | libreoffice | libreoffice | < 24.2.3.1 | Yes |
| Operating System | fedoraproject | fedora | 39 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |