CVE-2025-45869
the affected product
LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host.
- CVSS
- 7.3
- EPSS
- 0.20% 10.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.14