Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54092 | The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automation Scripting is needed to carry out the attack. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC. |
Solution
No solution given by the vendor.
Workaround
This vulnerability has been mitigated in LogicalDOC Community and Enterprise Editions version 9.1 by this commit and commit e7cd313.
| Link | Providers |
|---|---|
| https://www.blackduck.com/blog/cyrc-advisory-logicaldoc.html |
|
Fri, 07 Nov 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Logicaldoc
Logicaldoc logicaldoc |
|
| CPEs | cpe:2.3:a:logicaldoc:logicaldoc:*:*:*:*:community:*:*:* cpe:2.3:a:logicaldoc:logicaldoc:*:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Logicaldoc
Logicaldoc logicaldoc |
|
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automation Scripting is needed to carry out the attack. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC. | |
| Title | Remote Code Execution (RCE) via Automation Scripting | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: BlackDuck
Published:
Updated: 2025-03-18T16:36:58.362Z
Reserved: 2024-12-02T14:24:46.526Z
Link: CVE-2024-54448
Updated: 2025-03-17T16:20:51.453Z
Status : Analyzed
Published: 2025-03-14T18:15:30.617
Modified: 2025-11-07T02:21:41.283
Link: CVE-2024-54448
No data.
OpenCVE Enrichment
No data.
EUVD