LogicalDOC Enterprise up to and for v9
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.
CVSS Score
8.8
HIGH
Published
16 Jul 2026 16:18
Modified
20 Jul 2026 17:17
Source
CIRCL
CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Complexity
Low
Privileges
Low
Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Weaknesses (CWE)
CWE-89
Affected Systems
No vendor data available.
External Links
KEV Status
Not in CISA KEV catalog