CVE-2020-10365

CVE-2020-10365

LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database.

Source: CVE-2020-10365

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다