CyberRota Analysis
AI-GeneratedThe Seeyon A6 collaborative office automation platform is vulnerable to an unauthenticated SQL injection in the attach_ids parameter of its file attachment download endpoint, allowing remote attackers to extract arbitrary database contents. This vulnerability can lead to the exposure of sensitive information, including credentials and system configuration data, without requiring prior authentication. Organizations using Seeyon A6 should prioritize patching this vulnerability to mitigate the risk of data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.