CVE-2019-25684

Source
https://cve.org/CVERecord?id=CVE-2019-25684
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25684.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-25684
Published
2026-04-05T21:16:46.970Z
Modified
2026-07-27T09:24:00.710641Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.

References

Affected packages

Git / github.com/opendocman/opendocman

Affected ranges

Type
GIT
Repo
https://github.com/opendocman/opendocman
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "cpe": "cpe:2.3:a:opendocman:opendocman:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.4"
        }
    ]
}

Affected versions

1.*
1.2.6.1
1.2.6.2-release
1.2.6.2a
1.2.6.2b-release
1.2.6.3-release
1.2.6.3a
1.2.6.4-release
1.2.6.5-release
1.2.6.6-release
1.2.6.7-release
1.2.7.0
1.2.7.1
1.2.7.2
1.2.7.3
1.2.8
1.3.1
1.3.2
1.3.4
v1.*
v1.2.6.8
v1.2.8.1
v1.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25684.json"