CVE 8.1 HIGH

Apache OpenOffice: Remote documents loaded without prompt via “external data sources” in Calc_CVE-2025-64403

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Description

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links
to be loaded without prompt.

This issue affects Apache OpenOffice: through 4.1.15.

Users are recommended to upgrade to version 4.1.16, which fixes the issue.

Basic Information

ID CVE-2025-64403
Source apache
Published Nov 12, 2025 at 09:04
Modified Nov 12, 2025 at 14:47

Affected Product

Vendor Apache Software Foundation
Product Apache OpenOffice
Affected Versions Apache Software Foundation Apache OpenOffice 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.