CVE-2025-68935 | ONLYOFFICE Document Server up to 9.2.0 Setting Font cross site scripting (EUVD-2025-205393)
A vulnerability categorized as problematic has been discovered in ONLYOFFICE Document Server up to 9.2.0. The impacted element is an unknown function of the component Setting Handler. Such manipulation of the argument Font leads to cross site scripting.
This vulnerability is traded as CVE-2025-68935. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.