CyberRota Analysis
AI-GeneratedLogicalDOC Enterprise versions up to and including 9.1.1 are susceptible to Local File Inclusion (LFI) vulnerabilities in the OnlyOfficeEditor servlet, which can be exploited by authenticated users to access sensitive files through path traversal in the fileExt parameter. This could lead to unauthorized exposure of confidential data stored outside intended directories. Organizations using affected versions should prioritize remediation to mitigate potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories.