Junglewise Threat Intelligence

CVE-2025-45869: LogicalDOC Enterprise SSRF in ShareFileCallback servlet

CVE-2025-45869 · Severity: info · CVSS 0 · Published 2026-07-13

Technologies: LogicalDOC Enterprise. Vendors: LogicalDOC.

Executive brief

LogicalDOC Enterprise, a document management system used by organizations to store and collaborate on files, is vulnerable to a security flaw in its ShareFile integration. An unauthenticated attacker can trick the server into sending sensitive connection credentials (OAuth client IDs and secrets) to a server they control. This could allow an attacker to gain unauthorized access to documents and data stored in the connected ShareFile account.

Technical details

An unauthenticated SSRF exists in the ShareFileCallback servlet of LogicalDOC Enterprise (<= 9.1.1) due to insufficient validation of the 'apicp' and 'subdomain' parameters. An attacker can manipulate these parameters to redirect the server's outbound OAuth token request to an attacker-controlled host. During this request, the server transmits the configured ShareFile OAuth client_id and client_secret. Furthermore, because the 'state' parameter (used to identify users) is sequential, an attacker may be able to enumerate and exfiltrate credentials for multiple users. The vendor has indicated a fix will be available in version 9.2.

Affected products

  • LogicalDOC LogicalDOC Enterprise <= 9.1.1

Timeline

  • 2026-07-13: advisory: NVD publication date
  • 2026-07-13: disclosed: Public disclosure of vulnerability details

References

Related threats