CVE-2019-25257: LogicalDOC Enterprise 7.7.4 Authenticated Command Execution via Binary Path Manipulation
LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25257?
CVE-2019-25257 is rated as a high severity vulnerability due to its potential for authenticated OS command execution.
How do I fix CVE-2019-25257?
To fix CVE-2019-25257, update LogicalDOC Enterprise to the latest version that addresses these security vulnerabilities.
What kind of attack does CVE-2019-25257 enable?
CVE-2019-25257 enables authenticated attackers to exploit OS command execution vulnerabilities to manipulate system binaries.
Is CVE-2019-25257 specific to certain versions of LogicalDOC?
Yes, CVE-2019-25257 specifically affects LogicalDOC Enterprise version 7.7.4.
What can attackers do with CVE-2019-25257?
Attackers can exploit CVE-2019-25257 to modify configuration parameters that may lead to further system compromise.