LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
History

Wed, 05 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H'}

threat_severity

Important


Tue, 04 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Description LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
Title Macro URL arbitrary script execution
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Document Fdn.

Published: 2025-03-04T20:04:10.946Z

Updated: 2025-03-04T20:35:03.500Z

Reserved: 2025-02-06T13:14:08.175Z

Link: CVE-2025-1080

cve-icon Vulnrichment

Updated: 2025-03-04T20:35:00.173Z

cve-icon NVD

Status : Received

Published: 2025-03-04T20:15:36.867

Modified: 2025-03-04T20:15:36.867

Link: CVE-2025-1080

cve-icon Redhat

Severity : Important

Publid Date: 2025-03-04T20:04:10Z

Links: CVE-2025-1080 - Bugzilla