LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and /convertpdf endpoints to access sensitive system files like win.ini and /etc/passwd by manipulating path traversal sequences.
History

Fri, 09 Jan 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:logicaldoc:logicaldoc:7.1.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:logicaldoc:logicaldoc:7.4.2:*:*:*:enterprise:*:*:*
cpe:2.3:a:logicaldoc:logicaldoc:7.5.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:logicaldoc:logicaldoc:7.6.2:*:*:*:enterprise:*:*:*
cpe:2.3:a:logicaldoc:logicaldoc:7.6.4:*:*:*:enterprise:*:*:*
cpe:2.3:a:logicaldoc:logicaldoc:7.7.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:logicaldoc:logicaldoc:7.7.2:*:*:*:enterprise:*:*:*
cpe:2.3:a:logicaldoc:logicaldoc:7.7.3:*:*:*:enterprise:*:*:*
cpe:2.3:a:logicaldoc:logicaldoc:7.7.4:*:*:*:enterprise:*:*:*

Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Logicaldoc
Logicaldoc logicaldoc
Vendors & Products Logicaldoc
Logicaldoc logicaldoc

Wed, 24 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and /convertpdf endpoints to access sensitive system files like win.ini and /etc/passwd by manipulating path traversal sequences.
Title LogicalDOC Enterprise 7.7.4 Multiple Post-Authentication Directory Traversal Vulnerabilities
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-24T19:28:06.519Z

Updated: 2025-12-24T20:21:23.564Z

Reserved: 2025-12-24T14:27:12.479Z

Link: CVE-2019-25258

cve-icon Vulnrichment

Updated: 2025-12-24T20:00:35.747Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-24T20:15:54.627

Modified: 2026-01-09T20:50:45.407

Link: CVE-2019-25258

cve-icon Redhat

No data.