CVE-2025-10254 - CVE House
Back to Database
Status published Medium CVE-2025-10254

Ascensio System SIA OnlyOffice SVG Image Messages.aspx cross site scripting

Vulnerability Description

A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of the file /Products/Projects/Messages.aspx of the component SVG Image Handler. Performing manipulation results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was informed early about this issue and replied: "We are already working on this case, and the issues will be resolved in one of the upcoming patches."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10254

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • 0xHamy (VulDB User)

Affected Vendor

Ascensio System SIA

View all reports →

Affected Software

OnlyOffice
Vulnerable Versions:
12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7.0

Timeline

Official Publish: September 11th, 2025
Last Modified: September 11th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C

Weaknesses (CWE)