GHSA-2xg3-76qw-g9mmHighCVSS 7.5
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that...
🔗 CVE IDs covered (1)
📋 Description
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2023-54402
- https://blog.csdn.net/qq_41904294/article/details/134995343
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/idoc/idocview-lfi.yaml
- https://www.vulncheck.com/advisories/idocview-ssrf-via-doc-upload-endpoint-hardcoded-token
- https://github.com/advisories/GHSA-2xg3-76qw-g9mm