Description
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Information disclosure via SSRF, allowing remote unauthenticated attackers to retrieve arbitrary local or internal files
Action: Patch Immediately
AI Analysis

Impact

iDocView has a server‑side request forgery flaw in its /doc/upload endpoint that lets attackers supply the hardcoded token value "testtoken" to bypass authentication. The endpoint accepts any URL scheme, including file://, permitting the download of arbitrary local files and access to internal network hosts that are normally unreachable from the public internet. The vulnerability can expose sensitive configuration files, operating‑system data, and other confidential information, potentially undermining data confidentiality and facilitating further attacks.

Affected Systems

The flaw affects iDocView software, but the CVE entry does not specify exact version ranges. Administrators should verify whether the installed instance permits unauthenticated access to the /doc/upload endpoint and whether it accepts the default token "testtoken".

Risk and Exploitability

With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an external, unauthenticated HTTP request to the /doc/upload endpoint. The attacker can craft a request to an arbitrary external or internal URL, causing the iDocView server to fetch the content and effectively read sensitive files or communicate with services inside the internal network.

Generated by OpenCVE AI on September 30, 2026 at 21:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update iDocView to a version that removes the SSRF flaw or disables the /doc/upload endpoint
  • Configure the web application firewall to block requests containing the hardcoded token "testtoken" or to reject file:// and other insecure schemes
  • Restrict the /doc/upload endpoint to authenticated users or enforce a strong authentication token if the functionality is required

Generated by OpenCVE AI on September 30, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.
Title iDocView SSRF via /doc/upload Endpoint Hardcoded Token
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T20:22:33.022Z

Reserved: 2026-09-30T20:21:01.218Z

Link: CVE-2023-54402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:51.980

Modified: 2026-09-30T21:16:51.980

Link: CVE-2023-54402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:00:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)