CVE-2025-1080

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
CVSS

No CVSS.

Configurations

No configuration.

History

04 Mar 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 20:15

Updated : 2025-03-04 20:15


NVD link : CVE-2025-1080

Mitre link : CVE-2025-1080

CVE.ORG link : CVE-2025-1080


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation