CVE-2023-54402: iDocView SSRF via /doc/upload Endpoint Hardcoded Token
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
iDocView deployments with the /doc/upload endpoint reachable to remote users are exposed if the hardcoded default token value testtoken can be used to bypass authentication.
Does exploitation require credentials or user interaction?
No. The vulnerability can be exploited remotely without authentication or user interaction by supplying the hardcoded token value.
Has exploitation been observed in the wild?
Yes. The Shadowserver Foundation first observed exploitation evidence on 2024-03-26.