Impact
A vulnerability was identified in Newgen OmniDocs versions up to 12.0.00 that affects the /omnidocs/WebApiRequestRedirection endpoint. Manipulation of the DocumentId parameter gives an adversary improper control of resource identifiers - a CWE-99 issue - which can enable an attacker to request resources that should not be accessible or redirect the application to unintended content. This flaw allows remote exploitation and can lead to unauthorized disclosure of data or unexpected behavior within the OmniDocs platform.
Affected Systems
The flaw is present in all releases of Newgen OmniDocs up to and including version 12.0.00, with no additional sub-version constraints reported.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the publicly released exploit suggests that attackers already have usable code. The absence of an EPSS score and the fact that the vulnerability is not listed in the CISA KEV catalog do not diminish the real-world risk, as the flaw can be triggered from a remote location without authentication, as inferred from the description. Therefore, the risk remains high until a patch is applied or the vulnerable endpoint is otherwise mitigated.
OpenCVE Enrichment