PT-2026-60509 · Unknown · Logicaldoc Enterprise
CVE-2025-45870
·
Published
2026-07-16
·
Updated
2026-07-20
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LogicalDOC Enterprise versions prior to 9.1.2
Description
An authenticated user can exploit a Local File Inclusion (LFI) flaw in the
OnlyOfficeEditor servlet class. By utilizing path traversal in the fileExt parameter, an attacker can gain unauthorized access to sensitive files located outside the intended directories. Local File Inclusion is a vulnerability that allows an attacker to read files on the server that they should not have access to.Recommendations
Update LogicalDOC Enterprise to version 9.1.2 or later.
As a temporary mitigation, restrict access to the
OnlyOfficeEditor servlet class or avoid using the fileExt parameter until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logicaldoc Enterprise