Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-9849 — CVE-2019-9849: Remote bullet graphics retrieved in “stealth mode” in LibreOffice | Kitploit
Tools/GitHubGitHub/mbadanoiu/cve-2019-9849
Vulnerability AnalysisExploitationWeb SecurityPenetration Testing
GitHubmbadanoiu/cve-2019-9849

CVE-2019-9849

CVE-2019-9849: Remote bullet graphics retrieved in “stealth mode” in LibreOffice

View Repository
2 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-9849: Remote bullet graphics retrieved in “stealth mode” in LibreOffice

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources.
This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document.
A flaw existed where bullet graphics were omitted from this protection prior to version 6.2.5.

HTML TagHTML AttributeTriggers When OpenedTriggers On Save/Export
olsrcNoYes
ulsrcNoYes

Vendor Disclosure:

The vendor's disclosure for this vulnerability can be found here.

Proof Of Concept:

More details and the exploitation process (plus other HTML tag-attribute combination that result in SSRF) can be found in this PDF.

Download Tool