PT-2019-19821 · Logicaldoc · Logicaldoc Community Edition

Published

2019-05-30

·

Updated

2019-06-11

·

CVE-2019-9723

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions LogicalDOC Community Edition versions 8.0 through 8.2.0
Description The issue allows for path traversal, enabling the reading of arbitrary files and the creation of directories. This is due to a vulnerability in the PluginRegistry class.
Recommendations For versions 8.0 through 8.2.0, update to version 8.2.1 to resolve the issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9723

Affected Products

Logicaldoc Community Edition