CVE-2022-48422: ONLYOFFICE Document Server
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
Affected products
- ONLYOFFICE Document Server: up to and including 7.3.0
Published 2023-03-19. Last modified 2026-06-17.