LogicalDOC Enterprise up to and including v9.1.1 is vulnerable to Local File Inclusion (LFI) via the OnlyOfficeEditor servlet class. This vulnerability allows an authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside designated directories. The vulnerability has a significant impact on confidentiality and could lead to data brea [truncated]
LogicalDOC Enterprise up to and including v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component. This allows authenticated users to manipulate SQL queries via crafted input, potentially leading to data breaches or system compromise. The vulnerability affects operators, platforms, and security teams responsible for maintaining LogicalDOC Enterprise deployments. Users should assess [truncated]
LogicalDOC Enterprise version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host. This vulnerability has a high CVSS score of 7.3, indicating a high severity. Users of LogicalDOC Enterprise version up to and before [truncated]