LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.
References
Configurations
No configuration.
History
20 Jul 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
16 Jul 2026, 16:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-16 16:18
Updated : 2026-07-20 17:17
NVD link : CVE-2025-45868
Mitre link : CVE-2025-45868
CVE.ORG link : CVE-2025-45868
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
