CVE-2025-45869

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host.

Published 2026-07-13. Last modified 2026-07-13.