There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a crafted link to trigger the vulnerability. Stealing the session cookie is not possible due to cookie security flags, however the XSS may be used to induce a victim to perform on-site requests without their knowledge.

This vulnerability only affects LogicalDOC Enterprise.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54140 There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a crafted link to trigger the vulnerability. Stealing the session cookie is not possible due to cookie security flags, however the XSS may be used to induce a victim to perform on-site requests without their knowledge. This vulnerability only affects LogicalDOC Enterprise.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Logicaldoc
Logicaldoc logicaldoc
CPEs cpe:2.3:a:logicaldoc:logicaldoc:8.9.3:*:*:*:enterprise:*:*:*
Vendors & Products Logicaldoc
Logicaldoc logicaldoc
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00178}

epss

{'score': 0.00242}


Tue, 18 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Description There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a crafted link to trigger the vulnerability. Stealing the session cookie is not possible due to cookie security flags, however the XSS may be used to induce a victim to perform on-site requests without their knowledge. This vulnerability only affects LogicalDOC Enterprise.
Title Reflected Cross-Site Scripting (XSS)
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: BlackDuck

Published:

Updated: 2025-03-18T14:09:12.073Z

Reserved: 2024-12-02T14:24:54.703Z

Link: CVE-2024-12020

cve-icon Vulnrichment

Updated: 2025-03-18T14:09:08.885Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-14T18:15:27.370

Modified: 2025-11-07T02:19:49.930

Link: CVE-2024-12020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.