CVE-2020-10365: SQL Injection
LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10365?
CVE-2020-10365 has been assigned a Medium severity level due to its potential for SQL Injection vulnerabilities.
How do I fix CVE-2020-10365?
To fix CVE-2020-10365, upgrade LogicalDoc to version 8.3.3 or later, where the vulnerability is addressed.
Who is affected by CVE-2020-10365?
Any user or organization using LogicalDoc versions prior to 8.3.3 is affected by CVE-2020-10365.
What type of vulnerability is CVE-2020-10365?
CVE-2020-10365 is a SQL Injection vulnerability that allows attackers to perform arbitrary SQL queries.
Can CVE-2020-10365 be exploited remotely?
CVE-2020-10365 can be exploited remotely by an authenticated attacker.