CVE-2020-10365
Summary
| CVE | CVE-2020-10365 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-18 22:15:00 UTC |
| Updated | 2020-03-27 14:06:00 UTC |
| Description | LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Logicaldoc | Logicaldoc | All | All | All | All |
| Application | Logicaldoc | Logicaldoc | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| LogicalDoc Virtual Appliance Multiple Vulnerabilities | MISC | www.coresecurity.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.