CVE-2025-45870: LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEdi...
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories.
Security readout for executives and security teams
Plain-English summary
This flaw could let a logged-in LogicalDOC Enterprise user read sensitive server files that should be outside the application’s document area. It is not described as unauthenticated or actively exploited, but the confidentiality impact is high for affected deployments.
Executive priority
Address in the next vulnerability management cycle, faster for externally reachable systems or environments holding sensitive documents. The issue is not currently supported as actively exploited, but it can expose confidential files to authenticated users.
Technical view
CVE-2025-45870 is a CWE-22 path traversal issue in LogicalDOC Enterprise up to v9.1.1. The OnlyOfficeEditor servlet class mishandles the fileExt parameter, enabling authenticated local file inclusion and unauthorized file reads outside intended directories. CVSS v3.1 is 6.5 medium: network, low complexity, low privileges, no user interaction, high confidentiality impact.
Likely exposure
Exposure is likely limited to organizations running LogicalDOC Enterprise v9.1.1 or earlier. The CVE requires an authenticated user. The provided CVE data does not include CPEs, so defenders should confirm exposure through product and version inventory rather than relying only on automated CPE matching.
Exploitation context
The source bundle does not cite active exploitation, and the CVE is not marked in KEV. Public disclosure includes a GitHub vulnerability write-up, so technical details may be available to researchers and attackers. Treat internet-accessible or broadly user-accessible deployments as higher priority.
Researcher notes
Evidence supports authenticated LFI/path traversal with confidentiality impact only. The affected metadata is sparse: vendor/product fields and CPEs are not populated in the CVE record. Do not assume unauthenticated exploitation, integrity impact, availability impact, or a specific patched version from the supplied sources.
Mitigation direction
Check LogicalDOC vendor guidance and release notes for an official fix or workaround.
Prioritize upgrading affected LogicalDOC Enterprise instances when vendor-fixed versions are confirmed.
Restrict LogicalDOC access to trusted networks and necessary authenticated users.
Review user permissions and remove unnecessary accounts with access to document editing features.
Monitor application and web logs for suspicious file-access patterns.
Validation and detection
Inventory LogicalDOC Enterprise deployments and confirm exact versions.
Flag v9.1.1 and earlier as potentially affected.
Confirm whether OnlyOffice editing functionality is enabled and reachable by authenticated users.
Review logs for unusual requests involving document editor functionality and extension handling.
Track LogicalDOC advisories for patch confirmation and retest after remediation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-22: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.