vendor:
LogicalDOC Enterprise
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: LogicalDOC Enterprise
Affected Version From: 7.7.4
Affected Version To: 7.1.1
Patch Exists: YES
Related CWE: N/A
CPE: a:logicaldoc:logicaldoc_enterprise
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10, Linux Ubuntu 16.04, Java 1.8.0_161, Apache-Coyote/1.1, Apache Tomcat/8.5.24, Apache Tomcat/8.5.13, Undisclosed 8.41
2018
LogicalDOC Enterprise 7.7.4 Multiple Directory Traversal Vulnerabilities
The application suffers from multiple post-auth file disclosure vulnerability when input passed thru the 'suffix' and 'fileVersion' parameters is not properly verified before being used to include files. This can be exploited to read arbitrary files from local resources with directory traversal attacks.
Mitigation:
Input validation should be used to prevent directory traversal attacks.