CVE-2025-45869: LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF).
LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host.
Security readout for executives and security teams
Plain-English summary
CVE-2025-45869 is a high-severity SSRF issue in LogicalDOC Enterprise versions before v9.1.1. An unauthenticated attacker may cause the server to make outbound requests to an attacker-controlled host. Business risk depends on whether LogicalDOC is internet-facing and what internal services the server can reach.
Executive priority
Treat as a high-priority application risk if LogicalDOC is externally reachable. The issue is unauthenticated and can create a bridge from the application server to internal or attacker-controlled destinations. Confirm version exposure and vendor remediation status promptly.
Technical view
The CVE describes CWE-918 server-side request forgery in the ShareFileCallback servlet. The reported attack path uses manipulated input parameters to trigger server-side requests. CVSS 3.1 is 7.3, with network attack vector, low complexity, no privileges, and no user interaction. The record does not list CPEs or detailed vendor remediation.
Likely exposure
Organizations running LogicalDOC Enterprise versions before v9.1.1 are potentially exposed, especially if the application is reachable from the internet or untrusted networks. The source bundle does not provide CPEs, deployment details, or asset discovery indicators.
Exploitation context
The CVE states exploitation is unauthenticated and network-accessible. CISA KEV is false in the provided data, and the sources do not establish active exploitation in the wild. Public disclosure details exist on GitHub, increasing the need for timely validation.
Researcher notes
Evidence is limited to the CVE description and referenced disclosure. The affected product is named in the title and description, but structured affected CPE data is absent. Do not assume active exploitation or a specific fix beyond checking LogicalDOC guidance and validating versions before v9.1.1.
Mitigation direction
Check LogicalDOC vendor guidance and release notes for the corrected version or workaround.
Prioritize upgrading LogicalDOC Enterprise if running a version before v9.1.1.
Restrict internet access to LogicalDOC where business requirements allow.
Limit the LogicalDOC server’s outbound network access to required destinations.
Monitor requests involving ShareFileCallback and unusual outbound connections.
Validation and detection
Inventory all LogicalDOC Enterprise instances and record exact versions.
Confirm whether any instance is before v9.1.1.
Determine whether LogicalDOC is internet-facing or reachable by untrusted users.
Review logs for ShareFileCallback activity and unexpected outbound destinations.
Verify compensating egress controls are enforced on LogicalDOC hosts.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-918: Information exposure and cloud metadata lookup
Information exposure and SSRF weaknesses can make discovery, cloud metadata, and credential material review relevant. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references SSRF or metadata access, so cloud discovery and credential material review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-918 · source CWE mapping
Server-Side Request Forgery (SSRF)
Server-Side Request Forgery (SSRF) represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.