LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-18T21:24:09
Updated: 2024-08-04T10:58:40.346Z
Reserved: 2020-03-10T00:00:00
Link: CVE-2020-10365
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-03-18T22:15:12.250
Modified: 2024-11-21T04:55:09.597
Link: CVE-2020-10365
Redhat
No data.