CVE-2025-45868
Last modified
CVE-2025-45868 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-45868?
How severe is CVE-2025-45868?
How do I fix CVE-2025-45868?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-45862TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to cont…6.5
- CVE-2025-45863TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to cont…9.8
- CVE-2025-45864TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to cont…5.4
- CVE-2025-45865TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to cont…9.8
- CVE-2025-45866TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to cont…5.4
- CVE-2025-45867TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to cont…5.4
- CVE-2025-45869LogicalDOC Enterprise Version up to and before v9.1.1 is vul…7.3
- CVE-2025-4587The A/B Testing for WordPress plugin for WordPress is vulner…6.4
- CVE-2025-45870LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to …6.5
- CVE-2025-45872zrlog v3.1.5 was discovered to contain a Server-Side Request…9.8
- CVE-2025-45878A cross-site scripting (XSS) vulnerability in the report man…6.1
- CVE-2025-45879A cross-site scripting (XSS) vulnerability in the e-mail man…6.1
Are you affected by CVE-2025-45868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
