ONLYOFFICE Docs up to and including 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
onlyoffice document_server |