CVE-2023-37290

HIGH

InfoDoc Document System - Unauthenticated SSRF via HTML to PDF Conversion

Title source: llm
STIX 2.1

Description

InfoDoc Document On-line Submission and Approval System lacks sufficient restrictions on the available tags within its HTML to PDF conversion function, and allowing an unauthenticated attackers to load remote or local resources through HTML tags such as iframe. This vulnerability allows unauthenticated remote attackers to perform Server-Side Request Forgery (SSRF) attacks, gaining unauthorized access to arbitrary system files and uncovering the internal network topology.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 42.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
infodoc/document_on-line_submission_and_approval_system 22547
infodoc/document_on-line_submission_and_approval_system 22567
Published Jul 20, 2023
Tracked Since Feb 18, 2026