{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aidocviewidocview/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:idocview:idocview:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2023-54402"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iDocView"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["iDocView"],"content_html":"\u003cp\u003eiDocView contains a critical server-side request forgery (SSRF) vulnerability identified as CVE-2023-54402. The vulnerability resides in the /doc/upload endpoint, where inadequate input validation permits remote unauthenticated attackers to supply a hardcoded default token, 'testtoken', to bypass authentication mechanisms. Once authenticated, the endpoint allows the retrieval of arbitrary URLs. Because the implementation lacks sufficient restriction on URL schemes, attackers can leverage file:// URIs to perform local file disclosure, potentially exposing sensitive operating system or application configuration files. Furthermore, the vulnerability enables attackers to perform internal reconnaissance by reaching network services that are typically isolated from external traffic. Exploitation of this vulnerability has been observed in the wild since at least March 26, 2024, as documented by the Shadowserver Foundation. Defenders should prioritize patching or restricting access to the affected endpoint to prevent unauthorized information disclosure and internal network pivot attempts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing instance of iDocView hosting the vulnerable /doc/upload endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the /doc/upload endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the hardcoded value 'testtoken' in the request to bypass initial authentication requirements.\u003c/li\u003e\n\u003cli\u003eAttacker injects a target URL or URI into the request parameters to initiate the server-side request.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the file:// URI scheme to read sensitive system files (e.g., /etc/passwd or configuration files) from the application server.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes HTTP/HTTPS URI schemes to probe internal network segments, services, or metadata endpoints not accessible from the public internet.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates discovered internal host information or sensitive local file contents to an external listener.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-54402 leads to unauthorized local file disclosure and the ability for an attacker to bypass network perimeter controls. By accessing internal services and configuration files, attackers can gain credentials, architectural insights, or administrative access to the underlying server and connected internal network, posing a significant risk to organizational confidentiality and infrastructure integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict external network access to the iDocView /doc/upload endpoint if business requirements permit, or implement strict WAF filtering to intercept requests containing the 'testtoken' bypass value.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to webserver logs to monitor for incoming HTTP requests targeting the /doc/upload endpoint with suspicious query parameters.\u003c/li\u003e\n\u003cli\u003eMonitor egress traffic from iDocView servers for anomalous network connections to internal IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or common cloud metadata services.\u003c/li\u003e\n\u003cli\u003eAudit application logs for evidence of access to the /doc/upload endpoint using the hardcoded 'testtoken' value.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T22:37:02Z","date_published":"2026-09-30T22:37:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-idocview-ssrf/","summary":"The iDocView /doc/upload endpoint is susceptible to unauthenticated server-side request forgery (SSRF), allowing remote attackers to read sensitive local files and scan internal network infrastructure.","title":"iDocView SSRF Vulnerability (CVE-2023-54402)","url":"https://feed.craftedsignal.io/briefs/2026-09-idocview-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:idocview:idocview:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}