iDocView SSRF Vulnerability (CVE-2023-54402)
The iDocView /doc/upload endpoint is susceptible to unauthenticated server-side request forgery (SSRF), allowing remote attackers to read sensitive local files and scan internal network infrastructure.
CVE search metadata
CVE search record: CVE-2023-54402. Severity: high. CVSS: 7.5. KEV: no. Product: iDocView. Brief: iDocView SSRF Vulnerability (CVE-2023-54402). Brief link: https://feed.craftedsignal.io/briefs/2026-09-idocview-ssrf/
iDocView contains a critical server-side request forgery (SSRF) vulnerability identified as CVE-2023-54402. The vulnerability resides in the /doc/upload endpoint, where inadequate input validation permits remote unauthenticated attackers to supply a hardcoded default token, 'testtoken', to bypass authentication mechanisms. Once authenticated, the endpoint allows the retrieval of arbitrary URLs. Because the implementation lacks sufficient restriction on URL schemes, attackers can leverage file:// URIs to perform local file disclosure, potentially exposing sensitive operating system or application configuration files. Furthermore, the vulnerability enables attackers to perform internal reconnaissance by reaching network services that are typically isolated from external traffic. Exploitation of this vulnerability has been observed in the wild since at least March 26, 2024, as documented by the Shadowserver Foundation. Defenders should prioritize patching or restricting access to the affected endpoint to prevent unauthorized information disclosure and internal network pivot attempts.
Attack Chain
- Attacker identifies an internet-facing instance of iDocView hosting the vulnerable /doc/upload endpoint.
- Attacker crafts an HTTP POST request targeting the /doc/upload endpoint.
- Attacker includes the hardcoded value 'testtoken' in the request to bypass initial authentication requirements.
- Attacker injects a target URL or URI into the request parameters to initiate the server-side request.
- Attacker utilizes the file:// URI scheme to read sensitive system files (e.g., /etc/passwd or configuration files) from the application server.
- Attacker utilizes HTTP/HTTPS URI schemes to probe internal network segments, services, or metadata endpoints not accessible from the public internet.
- Attacker exfiltrates discovered internal host information or sensitive local file contents to an external listener.
Impact
Successful exploitation of CVE-2023-54402 leads to unauthorized local file disclosure and the ability for an attacker to bypass network perimeter controls. By accessing internal services and configuration files, attackers can gain credentials, architectural insights, or administrative access to the underlying server and connected internal network, posing a significant risk to organizational confidentiality and infrastructure integrity.
Recommendation
- Restrict external network access to the iDocView /doc/upload endpoint if business requirements permit, or implement strict WAF filtering to intercept requests containing the 'testtoken' bypass value.
- Deploy the provided Sigma rule to webserver logs to monitor for incoming HTTP requests targeting the /doc/upload endpoint with suspicious query parameters.
- Monitor egress traffic from iDocView servers for anomalous network connections to internal IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or common cloud metadata services.
- Audit application logs for evidence of access to the /doc/upload endpoint using the hardcoded 'testtoken' value.
Immediate actions
Patch iDocView instances or apply WAF rules to block requests containing 'testtoken' to /doc/upload.
Threat Hunt
Search web logs for /doc/upload usage containing 'testtoken' or 'file://'.
Data: Web server logs
Mitigations
Verify current version of iDocView and ensure it is not vulnerable.
CVE-2023-54402
Detection coverage 1
Detects CVE-2023-54402 Exploitation - SSRF in iDocView via /doc/upload
highDetects exploitation attempts against the /doc/upload endpoint using the known bypass token 'testtoken' and signs of SSRF via file protocol.
Detection queries are available on the platform. Get full rules →