CVE-2019-25258
Unknown
Unknown - Not Provided
Post-Auth File Disclosure in LogicalDOC 7.7.4 via Path Traversal
Publication date: 2025-12-24
Last updated on: 2025-12-24
Assigner: VulnCheck
Description
Description
LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and /convertpdf endpoints to access sensitive system files like win.ini and /etc/passwd by manipulating path traversal sequences.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| logicaldoc | enterprise | 7.7.4 |
| logicaldoc | enterprise | 7.4.2 |
| logicaldoc | enterprise | 7.6.4 |
| logicaldoc | enterprise | 7.1.1 |
| apache | tomcat | 8.5.24 |
| apache | tomcat | 8.5.13 |
| logicaldoc | enterprise | 7.7.1 |
| microsoft | windows | 10 |
| logicaldoc | enterprise | 7.6.2 |
| logicaldoc | enterprise | 7.7.3 |
| ubuntu | ubuntu | 16.04 |
| logicaldoc | enterprise | 7.5.1 |
| java | java | 1.8.0_161 |
| logicaldoc | enterprise | 7.7.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-22 | The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |