LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:58:40.346Z
Reserved: 2020-03-10T00:00:00
Link: CVE-2020-10365

No data.

Status : Modified
Published: 2020-03-18T22:15:12.250
Modified: 2024-11-21T04:55:09.597
Link: CVE-2020-10365

No data.