CVE-2025-55853
CRITICALSoftVision webPDF < 10.0.2 - Server-Side Request Forgery via PDF Converter Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-55853. PoCs published by Vivz13.
AI-analyzed exploit summary This repository contains a functional PoC for CVE-2025-55853, demonstrating an SSRF vulnerability in SoftVision webPDF before 10.0.2. The exploit leverages an HTML payload with an iframe to perform Local File Inclusion (LFI) via the file:// protocol.
Description
SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTML file in the application, which when rendered to a PDF allows for internal port scanning and Local File Inclusion (LFI).
Exploits (1)
This repository contains a functional PoC for CVE-2025-55853, demonstrating an SSRF vulnerability in SoftVision webPDF before 10.0.2. The exploit leverages an HTML payload with an iframe to perform Local File Inclusion (LFI) via the file:// protocol.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N