CVE-2025-45871EPSS p15.8%
CVE-2025-45871CVE-2025-45871
Description
LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.
Scoring
| CVSS | 8.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 0.26% probability of exploitation · percentile 15.8% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |