CVE-2015-20122: Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp
Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attachids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attachids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an account or user interaction?
No. The vulnerability is remotely exploitable without prior authentication or user interaction.
What information could an attacker obtain?
An attacker can extract arbitrary database contents, including sensitive information such as credentials and system configuration data.
Is there evidence of exploitation activity?
Yes. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.
Does the reported impact include modification or disruption of the service?
The provided severity vector indicates high confidentiality impact, with no integrity or availability impact reported.