Product
The iDocView /doc/upload endpoint is susceptible to unauthenticated server-side request forgery (SSRF), allowing remote attackers to read sensitive local files and scan internal network infrastructure.