PT-2025-11299 · Unknown · Logicaldoc

Matthew Hogg

·

Published

2025-03-14

·

Updated

2025-11-07

·

CVE-2024-54449

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LogicalDOC (affected versions not specified)
Description The application's API, used for document interaction, contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled content to an arbitrary location on the underlying file system. This can be used to facilitate Remote Code Execution (RCE). Exploitation requires an account with ‘read’ and ‘write’ privileges on at least one existing document within the application. Successful exploitation would allow an attacker to execute commands on the underlying operating system of the web server running LogicalDOC. The vulnerable API endpoints allow for arbitrary file writing. The file content is controlled by the attacker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-54449

Affected Products

Logicaldoc