LogicalDOC Enterprise Directory Traversal Vulnerability Allowing Arbitrary File Disclosure

Vulnerability

A post-authentication file disclosure vulnerability has been identified in LogicalDOC Enterprise version 7.7.4. This vulnerability allows attackers to read arbitrary files by exploiting unverified 'suffix' and 'fileVersion' parameters. The issue arises from improper validation of these parameters, which can be manipulated to perform directory traversal attacks. The vulnerability can be exploited through the '/thumbnail' and '/convertpdf' endpoints to access sensitive system files such as 'win.ini' and '/etc/passwd'.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive system files, potentially exposing critical information such as user credentials and system configurations.

Reproduction

The vulnerability can be reproduced by sending a GET request to the '/thumbnail' or '/convertpdf' endpoints with crafted 'suffix' or 'fileVersion' parameters that include directory traversal sequences. This request can be made using a web browser or a tool like curl or Postman.

Added: Dec 24, 2025, 8:20 PM
Updated: Dec 24, 2025, 9:26 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
2.5
exploitability
6.6
remediation
0.0
relevance
1.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.