Latest Security News about identity protection

Contact US For API Security>

LogicalDoc before 8.3.3 allows SQL Injection

  Overview : LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database. CVE ID :CVE-2020-10365 LogicalDoc [...]