SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2025-45870

MEDIUM · CVSS 6.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

LogicalDOC Enterprise versions up to and including 9.1.1 are susceptible to Local File Inclusion (LFI) vulnerabilities in the OnlyOfficeEditor servlet, which can be exploited by authenticated users to access sensitive files through path traversal in the fileExt parameter. This could lead to unauthorized exposure of confidential data stored outside intended directories. Organizations using affected versions should prioritize remediation to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-45870
Severity
MEDIUM
CVSS
6.5
EPSS
0.36%
Office

Original NVD Description

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories.