LogicalDOC是意大利LogicalDOC公司开源的一套使用Java技术开发的文件管理系统。该系统具有Lucene全文搜索索引和自动导入等功能。 LogicalDOC 9.1.1及之前版本存在安全漏洞,该漏洞源于OnlyOfficeEditor servlet类中路径遍历问题,允许经过身份验证的用户利用fileExt参数,可未授权访问指定目录之外的敏感文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-32386 | 7.3 HIGH | Kerlink KerOS 安全漏洞 |
| CVE-2024-34268 | 7.1 HIGH | EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware 安全漏洞 |
| CVE-2024-32387 | 5.7 MEDIUM | Kerlink KerOS 安全漏洞 |
| CVE-2024-32385 | 4.3 MEDIUM | Kerlink KerOS 安全漏洞 |
| CVE-2024-32389 | 3.5 LOW | Kerlink KerOS 安全漏洞 |
| CVE-2025-45868 | LogicalDOC 安全漏洞 | |
| CVE-2026-36425 | OPSWAT AppRemover Driver 安全漏洞 | |
| CVE-2026-38158 | ureport2 project UReport2 安全漏洞 |
No comments yet