SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2025-45868

HIGH · CVSS 8.8 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

LogicalDOC Enterprise versions up to 9.1.1 are susceptible to a blind SQL injection vulnerability in the ComparisonServlet component, enabling authenticated users to execute arbitrary SQL queries through specially crafted input. This flaw poses a significant risk as it can lead to unauthorized data access or manipulation. Organizations using affected versions should prioritize remediation to mitigate potential data breaches and integrity issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-45868
Severity
HIGH
CVSS
8.8
EPSS
0.28%

Original NVD Description

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.