CyberRota Analysis
AI-GeneratediDocView is vulnerable due to a server-side request forgery (SSRF) flaw in its /doc/upload endpoint, allowing remote unauthenticated attackers to bypass authentication using a hardcoded token. This vulnerability enables attackers to access arbitrary URLs, including local files and internal network services, posing a significant risk to sensitive data and system integrity. Organizations using iDocView should prioritize immediate remediation to mitigate potential data breaches and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.