LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.
References
Configurations
No configuration.
History
24 Dec 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/44021 - | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5452.php - |
24 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-24 20:15
Updated : 2025-12-29 15:58
NVD link : CVE-2019-25257
Mitre link : CVE-2019-25257
CVE.ORG link : CVE-2019-25257
JSON object : View
Products Affected
No product.
CWE
CWE-426
Untrusted Search Path
