LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host.
LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 73.00 |
| 利用信号(无额外利用信号) | ×1.00 |
| VPI | 73.00 |
VPI 公式 vpi-v1