HIGH🇵🇱 Wersja polska

CVE-2018-12942

CVSS 8.8v3.0pub. 2018-07-31upd. 2024-11-21

SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attackers to manipulate an SQL query within the application by sending additional SQL commands to the application server. An attacker can use this vulnerability to perform malicious tasks such as to extract, change, or delete sensitive information within the database supporting the application, and potentially run system commands on the underlying operating system.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Seeddms

    APP
    Seeddms
    < 5.1.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2022-44938CRITICAL9.8PL ✓same product

SeedDMS: słaby token resetowania hasła umożliwia przejęcie konta

CVE-2025-45752HIGH7.2same product

A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by ex...

CVE-2021-33223HIGH8.8same product

An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parame...

CVE-2019-12744HIGH7.5same product

SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts,...

CVE-2018-12940HIGH8.8same product

Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) bef...