CVE-2019-25258
EUVD-2025-20529624.12.2025, 20:15
LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and /convertpdf endpoints to access sensitive system files like win.ini and /etc/passwd by manipulating path traversal sequences.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| logicaldoc | logicaldoc | 7.1.1 |
| logicaldoc | logicaldoc | 7.4.2 |
| logicaldoc | logicaldoc | 7.5.1 |
| logicaldoc | logicaldoc | 7.6.2 |
| logicaldoc | logicaldoc | 7.6.4 |
| logicaldoc | logicaldoc | 7.7.1 |
| logicaldoc | logicaldoc | 7.7.2 |
| logicaldoc | logicaldoc | 7.7.3 |
| logicaldoc | logicaldoc | 7.7.4 |
𝑥
= Vulnerable software versions