6.5
CVSSv3

CVE-2020-10365

Published: 18/03/2020 Updated: 27/03/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

LogicalDoc prior to 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated malicious user to perform arbitrary queries to the database.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

logicaldoc logicaldoc