LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.
Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.