Unrated severityNVD Advisory· Published Dec 24, 2025· Updated Mar 5, 2026
LogicalDOC Enterprise 7.7.4 Multiple Post-Authentication Directory Traversal Vulnerabilities
CVE-2019-25258
Description
LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and /convertpdf endpoints to access sensitive system files like win.ini and /etc/passwd by manipulating path traversal sequences.
Affected products
2- Range: =7.7.4
- LogicalDOC Srl/LogicalDOC Enterprisev5Range: 7.7.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/44019mitreexploit
- www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5450.phpmitrethird-party-advisory
- www.logicaldoc.commitreproduct
News mentions
0No linked articles in our index yet.