OnlyOffice Setup Wizard Page Exposure Scanner
This scanner checks for publicly accessible OnlyOffice Setup Wizard (Wizard.aspx) endpoints, allowing attackers to reconfigure or extract sensitive installation data.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
19 days 7 hours
Scan only one
URL
Toolbox
OnlyOffice is a comprehensive open-source office suite used by enterprises, educational institutions, and non-profits for collaborative document editing, project management, and business communication. It supports popular file formats like DOCX, PPTX, and XLSX, making it a versatile tool for organizations seeking data privacy and customization. The platform is deployed on-premises or in the cloud, serving as a central hub for workflow efficiency.
The Setup Wizard Page Exposure vulnerability occurs when the installation wizard (Wizard.aspx) remains accessible after initial setup. This oversight allows unauthorized users to access the configuration interface, potentially leading to reinstallation or modification of critical settings. The vulnerability arises from improper access controls or failure to remove the wizard after deployment.
Technically, the scanner targets the /wizard/Wizard.aspx endpoint, which is used during OnlyOffice's initial configuration. If left exposed, an attacker can interact with this page to view or alter database connections, admin credentials, and other sensitive parameters. The vulnerability is rated CVSS 8.0 due to its high impact on confidentiality and integrity.
Exploitation could allow attackers to reset administrative accounts, change database configurations, or inject malicious settings. This compromises the entire OnlyOffice instance, leading to data breaches, service disruption, or unauthorized access to documents. Organizations risk significant operational and reputational damage if this exposure is not addressed.