CVE-2023-54402

Summary

iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.

Affected Software

VendorProductVersion RangeStatus
iDocViewiDocView*affected

Weaknesses

  • CWE-918: Server-Side Request Forgery (SSRF)

References