CVE-2025-45250
MEDIUMmrdoc < 0.95 - Server-Side Request Forgery via validate_url Function
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-45250. PoCs published by Anike-x, xp3s.
AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2025-45250, an SSRF vulnerability in MrDoc <=0.95. The exploit demonstrates how an attacker can trick the server into making malicious requests by sending a crafted POST request to the /upload_doc_img/ endpoint with a manipulated URL parameter.
Description
MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.
Exploits (2)
This repository contains a proof-of-concept for CVE-2025-45250, an SSRF vulnerability in MrDoc <=0.95. The exploit demonstrates how an attacker can trick the server into making malicious requests by sending a crafted POST request to the /upload_doc_img/ endpoint with a manipulated URL parameter.
This PoC demonstrates a Server-Side Request Forgery (SSRF) vulnerability in MrDoc <=0.95. The exploit involves sending a crafted POST request to the `/upload_doc_img/` endpoint with a malicious URL, allowing an attacker to trick the server into making requests to internal or external systems.
References (2)
Scores
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L