LogicalDOC Enterprise 7.7.4 Authenticated Command Execution via Binary Path Manipulation
Vulnerability Description
LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25257
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- LiquidWorm as Gjoko Krstic of Zero Science Lab
References
Affected Vendor
LogicalDOC Srl
View all reports →