CVE-2025-45871
Received Received - Intake

Blind SQL Injection in LogicalDOC Enterprise

Vulnerability report for CVE-2025-45871, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: MITRE

Description

LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a blind SQL injection in LogicalDOC Enterprise versions up to and including 9.1.1. It affects the WorkflowsDataServlet component and allows an authenticated user to manipulate SQL queries by injecting malicious input through the workflow template name parameter.

Detection Guidance

I don't know

Check LogicalDOC Enterprise logs for suspicious SQL query patterns or unauthorized workflow template modifications.

Impact Analysis

An attacker with valid credentials could exploit this to execute unauthorized SQL commands on the database. This may lead to data theft, unauthorized modifications, or complete system compromise depending on database permissions.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of sensitive data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations may face compliance violations and penalties if exploited.

Mitigation Strategies

Upgrade LogicalDOC Enterprise to a version beyond 9.1.1 to address the SQL injection vulnerability in WorkflowsDataServlet.

Restrict database access permissions for authenticated users to minimize potential SQL manipulation risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-45871. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart