OnlyOffice Setup Wizard Page Exposure Scanner

This scanner checks for publicly accessible OnlyOffice Setup Wizard (Wizard.aspx) endpoints, allowing attackers to reconfigure or extract sensitive installation data.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

19 days 7 hours

Scan only one

URL

Toolbox

OnlyOffice is a comprehensive open-source office suite used by enterprises, educational institutions, and non-profits for collaborative document editing, project management, and business communication. It supports popular file formats like DOCX, PPTX, and XLSX, making it a versatile tool for organizations seeking data privacy and customization. The platform is deployed on-premises or in the cloud, serving as a central hub for workflow efficiency.

The Setup Wizard Page Exposure vulnerability occurs when the installation wizard (Wizard.aspx) remains accessible after initial setup. This oversight allows unauthorized users to access the configuration interface, potentially leading to reinstallation or modification of critical settings. The vulnerability arises from improper access controls or failure to remove the wizard after deployment.

Technically, the scanner targets the /wizard/Wizard.aspx endpoint, which is used during OnlyOffice's initial configuration. If left exposed, an attacker can interact with this page to view or alter database connections, admin credentials, and other sensitive parameters. The vulnerability is rated CVSS 8.0 due to its high impact on confidentiality and integrity.

Exploitation could allow attackers to reset administrative accounts, change database configurations, or inject malicious settings. This compromises the entire OnlyOffice instance, leading to data breaches, service disruption, or unauthorized access to documents. Organizations risk significant operational and reputational damage if this exposure is not addressed.

Get started to protecting your digital assets