Skip to content

Latest commit

 

History

History
22 lines (13 loc) · 645 Bytes

CVE-2022-47502.md

File metadata and controls

22 lines (13 loc) · 645 Bytes

CVE-2022-47502

  • Macro URL arbitrary script execution without warning

refs

details

While doing variant analysis between libreoffice and openoffice codebases, i found a poc on twitter for a CVE of libreoffice which turned out to be a oday on openoffice (thank you friend for the free cve). And so i reported the vulnerability and after inspecting the patch i concluded that, while libreoffice and openoffice codebases are similar, the uri schema part was different.

poc

poc.gif