Impact
iDocView has a server‑side request forgery flaw in its /doc/upload endpoint that lets attackers supply the hardcoded token value "testtoken" to bypass authentication. The endpoint accepts any URL scheme, including file://, permitting the download of arbitrary local files and access to internal network hosts that are normally unreachable from the public internet. The vulnerability can expose sensitive configuration files, operating‑system data, and other confidential information, potentially undermining data confidentiality and facilitating further attacks.
Affected Systems
The flaw affects iDocView software, but the CVE entry does not specify exact version ranges. Administrators should verify whether the installed instance permits unauthenticated access to the /doc/upload endpoint and whether it accepts the default token "testtoken".
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an external, unauthenticated HTTP request to the /doc/upload endpoint. The attacker can craft a request to an arbitrary external or internal URL, causing the iDocView server to fetch the content and effectively read sensitive files or communicate with services inside the internal network.
OpenCVE Enrichment