Impact
LogicalDOC Enterprise versions 9.1.1 and earlier contain an unauthenticated SSRF flaw in the ShareFileCallback servlet. By sending a crafted HTTP request, an attacker can cause the server to issue a request to an attacker‑controlled host. This flaw allows the server to establish outbound connections to arbitrary destinations, potentially exposing internal metadata or enabling further attacks. No additional consequences such as file read or internal host scanning are confirmed by the source.
Affected Systems
Deployments running LogicalDOC Enterprise version 9.1.1 or earlier are affected. The vulnerability resides in the ShareFileCallback servlet.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. The EPSS score is less than 1%, showing a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by sending an unauthenticated HTTP request to the vulnerable endpoint, which can then be adapted to reach arbitrary external hosts. The attack does not require authentication and therefore poses a significant risk to systems exposed on the public network.
OpenCVE Enrichment