← Back

CVE-2020-10365

nvd nist
Published: Mar 18, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database.

Affected (1)

1 product
Logicaldoc
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.3.3

References (2)

Timeline

No history available yet.