Description
LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host.
Published: 2026-07-13
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

LogicalDOC Enterprise versions 9.1.1 and earlier contain an unauthenticated SSRF flaw in the ShareFileCallback servlet. By sending a crafted HTTP request, an attacker can cause the server to issue a request to an attacker‑controlled host. This flaw allows the server to establish outbound connections to arbitrary destinations, potentially exposing internal metadata or enabling further attacks. No additional consequences such as file read or internal host scanning are confirmed by the source.

Affected Systems

Deployments running LogicalDOC Enterprise version 9.1.1 or earlier are affected. The vulnerability resides in the ShareFileCallback servlet.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity. The EPSS score is less than 1%, showing a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by sending an unauthenticated HTTP request to the vulnerable endpoint, which can then be adapted to reach arbitrary external hosts. The attack does not require authentication and therefore poses a significant risk to systems exposed on the public network.

Generated by OpenCVE AI on July 31, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of LogicalDOC Enterprise that removes the SSRF flaw (any version newer than 9.1.1).
  • Limit inbound traffic to the ShareFileCallback endpoint, allowing only trusted internal sources to access it.
  • Block outbound traffic from the LogicalDOC server to unknown external hosts using network firewall rules.
  • If the ShareFileCallback feature is not required, disable or remove it from the configuration.

Generated by OpenCVE AI on July 31, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in LogicalDOC Enterprise ShareFileCallback Servlet

Sat, 25 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title LogicalDOC Enterprise SSRF via ShareFileCallback Exploitable Without Authentication

Mon, 20 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title LogicalDOC Enterprise SSRF via ShareFileCallback Exploitable Without Authentication

Thu, 16 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated SSRF in LogicalDOC ShareFileCallback before v9.1.1

Tue, 14 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated SSRF in LogicalDOC ShareFileCallback before v9.1.1

Mon, 13 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-13T19:29:41.809Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-45869

cve-icon Vulnrichment

Updated: 2026-07-13T19:29:37.400Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)