Infodoc maintains a document submission and approval system product that occupies a narrow but strategic position in enterprise workflow infrastructure. Its vulnerability profile centers on server-side request forgery and unrestricted file upload weaknesses, both of which reflect the inherent risks of processing and storing user-supplied documents in a networked environment. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infodoc over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37289CRITICAL It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, whic | Jul 20, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-37290HIGH
InfoDoc Document On-line Submission and Approval System lacks sufficient restrictions on the available tags within its HTML to PDF conversion function, and allowing an unauthentic | Jul 20, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infodoc.
Media articles that mention a CVE ID that affects a product developed by Infodoc — matched by CVE ID, not by vendor name.