CVE-2023-54402
Received Received - Intake

Server-Side Request Forgery in iDocView

Vulnerability report for CVE-2023-54402, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a server-side request forgery (SSRF) in iDocView's /doc/upload endpoint. It allows unauthenticated remote attackers to bypass authentication using a hardcoded token (testtoken) and fetch arbitrary URLs. The system improperly handles URL schemes, including file:// URIs, enabling attackers to read local files like OS and app configs or access internal network hosts.

Detection Guidance

To detect this vulnerability, scan for systems running iDocView with the /doc/upload endpoint exposed. Check for unusual outbound requests or file:// URI handling. Use network scanners like Nmap to identify services on port 80 or 443 with the vulnerable endpoint. Example command: nmap -p 80,443 --script http-enum <target_IP>.

Impact Analysis

Attackers could exploit this to steal sensitive data from your system, such as configuration files or internal documents. They might also access internal services or hosts not exposed to the internet, potentially leading to further breaches or data leaks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately restrict access to the /doc/upload endpoint via firewall rules or disable it if unused. Update iDocView to the latest patched version if available. Monitor network traffic for suspicious outbound connections or file:// URI requests. Remove the hardcoded default token 'testtoken' if present.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54402. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart